Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Owasp/csp wildcard directive #1706

Merged
merged 8 commits into from
Nov 7, 2023
Merged

Owasp/csp wildcard directive #1706

merged 8 commits into from
Nov 7, 2023

Conversation

whabanks
Copy link
Contributor

@whabanks whabanks commented Nov 7, 2023

Summary | Résumé

Adds frame-ancestors and form-action to the Content-Security-Policy headers. Some adjustments to the form-action header may be necessary after initial round of testing in staging.

Addresses: https://github.com/orgs/cds-snc/projects/37/views/1?pane=issue&itemId=42791228

Copy link

github-actions bot commented Nov 7, 2023

@whabanks whabanks requested a review from jimleroyer November 7, 2023 19:44
@jimleroyer jimleroyer merged commit c8dc1b3 into main Nov 7, 2023
@jimleroyer jimleroyer deleted the owasp/csp-wildcard-directive branch November 7, 2023 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants