Re: Implementing CSP (Content Security Policy) for gitweb in the future
- From
Matt McCutchen <matt@mattmccutchen.net>
- Date
- Jun 5, 2011, 12:52 UTC
- Message-ID
- <1307278350.23564.5.camel@localhost>
- In-Reply-To
- <201106051103.59541.jnareb@gmail.com>
On Sun, 2011-06-05 at 11:03 +0200, Jakub Narebski wrote:
> In the future however it might be better solution for gitweb to implement > (as an option) support for CSP (Content Security Policy), which IIRC did > not exists in 2009, in addition to current $prevent_xss.
Sure. CSP is not a substitute for designing to prevent harmful HTML injection, but a mitigation for some of its worst effects in case some injection points are overlooked. There's no reason not to enable it by default with $prevent_xss, though third parties adding functionality to gitweb would need to know to disable it or modify the policy accordingly.
-- Matt