Uploaded image for project: 'OpenShift Console'
  1. OpenShift Console
  2. CONSOLE-4430

Automated Content Security Policy testing of Console pages

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • OCP Console - Sprint 267, OCP Console - Sprint 268

      In Console 4.18 we introduced an initial Content Security Policy (CSP) implementation (CONSOLE-4263).

      This affects both Console web application as well as any dynamic plugins loaded by Console. In production, CSP violations are sent to telemetry service for analysis (CONSOLE-4272).

      We need a reliable way to detect new CSP violations as part of our automated CI checks. We can start with testing the main dashboard page of Console and expand to more pages as necessary.

      Acceptance criteria:

      • Console project provides a script to test for CSP violations.
      • CSP violation test script does not report any errors for Console.

              vszocs@redhat.com Vojtech Szocs
              vszocs@redhat.com Vojtech Szocs
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: