Uploaded image for project: 'OpenShift Console'
  1. OpenShift Console
  2. CONSOLE-4263

Initial Content Security Policy implementation for Console

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • HAC Infra OCP - Sprint 260

      This story follows up on spike https://issues.redhat.com/browse/CONSOLE-4170

      The aim of this story is to add initial CSP implementation for Console web application that will use Content-Security-Policy-Report-Only HTTP header to report on CSP violations.

      CSP violations should be handled directly by Console code via custom SecurityPolicyViolationEvent handler, which logs the relevant CSP violation data to browser console.

      AC:

      • Console HTML index page must be served with CSP report-only response header
      • Running dynamic demo plugin in Console must not trigger any CSP violations
      • CSP violations must be logged to browser console
      • dynamic plugins README should contain a section that describes CSP usage in Console

              vszocs@redhat.com Vojtech Szocs
              jhadvig@redhat.com Jakub Hadvig
              YaDan Pei YaDan Pei
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: