We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
From @danielsotirhos in DataBiosphere/azul#4239:
There were 9 issues identified for https://dev.singlecell.gi.ucsc.edu/explore/ The same 9 issues and 4 others were identified for https://dev.singlecell.gi.ucsc.edu/ The 4 issues unique to https://dev.singlecell.gi.ucsc.edu/ (5, 6, 12, & 13) are marked with a [*]
HTTP Strict Transport Security (HSTS) Errors and Warnings
Cookie Not Marked as HttpOnly
Cookie Not Marked as Secure
Insecure Frame (External
Misconfigured Access-Control-Allow-Origin Header [*]
Passive Mixed Content over HTTPS [*]
Content Security Policy (CSP) NotImplemented
Expect-CT Not Enabled
SameSite Cookie Not Implemented
Subresource Integrity (SRI) NotImplemented
Cross-site Referrer Leakage through usage of strict-origin-when-cross-origin in Referrer-Policy
Email Address Disclosure [*]
Generic Email Address Disclosure [*]
The text was updated successfully, but these errors were encountered:
Superseded by #2709
Sorry, something went wrong.
@theathorn @NoopDog is there a ticket for the following findings
Level: Medium To be fixed by Clever Canary Cookie Not Marked as HttpOnly
Level: Low To be fixed by Clever Canary Cookie Not Marked as Secure
Level: Low To be fixed by Clever Canary
Superseded by #2789.
NoopDog
No branches or pull requests
From @danielsotirhos in DataBiosphere/azul#4239:
There were 9 issues identified for https://dev.singlecell.gi.ucsc.edu/explore/
The same 9 issues and 4 others were identified for https://dev.singlecell.gi.ucsc.edu/
The 4 issues unique to https://dev.singlecell.gi.ucsc.edu/ (5, 6, 12, & 13) are marked with a [*]
HTTP Strict Transport Security (HSTS) Errors and Warnings
Cookie Not Marked as HttpOnly
Cookie Not Marked as Secure
Insecure Frame (External
Misconfigured Access-Control-Allow-Origin Header [*]
Passive Mixed Content over HTTPS [*]
Content Security Policy (CSP) NotImplemented
Expect-CT Not Enabled
SameSite Cookie Not Implemented
Subresource Integrity (SRI) NotImplemented
Cross-site Referrer Leakage through usage of strict-origin-when-cross-origin in Referrer-Policy
Email Address Disclosure [*]
Generic Email Address Disclosure [*]
The text was updated successfully, but these errors were encountered: