Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-21838

Add Content Security Policy http headers in default eZ configuration

    XMLWordPrintable

Details

    • Icon: Improvement Improvement
    • Resolution: Duplicate
    • Icon: High High
    • None
    • None
    • None

    Description

      Following the principle of delivering a hardened platform out of the box (XSRF token, preventing cookie stealing etc), I think we should adopt the following countermeasure as well: CSP

      See for reference: http://en.wikipedia.org/wiki/Content_Security_Policy
      and for an example usage/explanation (even though that one involves usage of an external firewall): http://blog.spiderlabs.com/2013/10/phpnet-site-infected-with-malware.html

      Attachments

        Activity

          People

            Unassigned Unassigned
            gaetano.giunta-obsolete@ez.no Gaetano Giunta (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: