git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Implementing CSP (Content Security Policy) for gitweb in the future

From
Matt McCutchen <matt@mattmccutchen.net>
Date
Jun 5, 2011, 12:52 UTC
Message-ID
<1307278350.23564.5.camel@localhost>
In-Reply-To
<201106051103.59541.jnareb@gmail.com>
On Sun, 2011-06-05 at 11:03 +0200, Jakub Narebski wrote:
> In the future however it might be better solution for gitweb to implement
> (as an option) support for CSP (Content Security Policy), which IIRC did
> not exists in 2009, in addition to current $prevent_xss.

Sure. CSP is not a substitute for designing to prevent harmful HTML injection, but a mitigation for some of its worst effects in case some injection points are overlooked. There's no reason not to enable it by default with $prevent_xss, though third parties adding functionality to gitweb would need to know to disable it or modify the policy accordingly.

-- 
Matt
Previous: Jakub NarebskiNext: Jakub Narebski
Message 5 of 14 in “gitweb: Fix usability of $prevent_xss”
  1. gitweb: Fix usability of $prevent_xssJakub Narebski, Jun 4, 2011
  2. Prevalence of $prevent_xssMatt McCutchen, Jun 4, 2011
  3. Jakub NarebskiJun 4, 2011
  4. Implementing CSP (Content Security Policy) for gitweb in the futureJakub Narebski, Jun 5, 2011
  5. Matt McCutchenJun 5, 2011
  6. Jakub NarebskiJun 5, 2011
  7. Matt McCutchenJun 5, 2011
  8. Jakub NarebskiJun 8, 2011
  9. J.H.Jun 8, 2011
  10. gitweb: Make $prevent_xss protection for 'blob_plain' more usableJakub Narebski, Jun 10, 2011
  11. Junio C HamanoJun 13, 2011
  12. Jakub NarebskiJun 13, 2011
  13. Junio C HamanoJun 13, 2011
  14. Jakub NarebskiJun 14, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.