From: Matt McCutchen Date: Sun, 05 Jun 2011 12:52:30 GMT Subject: Re: Implementing CSP (Content Security Policy) for gitweb in the future Message-ID: <1307278350.23564.5.camel@localhost> In-Reply-To: <201106051103.59541.jnareb@gmail.com> On Sun, 2011-06-05 at 11:03 +0200, Jakub Narebski wrote: > In the future however it might be better solution for gitweb to implement > (as an option) support for CSP (Content Security Policy), which IIRC did > not exists in 2009, in addition to current $prevent_xss. Sure. CSP is not a substitute for designing to prevent harmful HTML injection, but a mitigation for some of its worst effects in case some injection points are overlooked. There's no reason not to enable it by default with $prevent_xss, though third parties adding functionality to gitweb would need to know to disable it or modify the policy accordingly. -- Matt