#508 - Support Content Security Policy

Identifier #508
Issue type Feature request or suggestion
Title Support Content Security Policy
Status Completed
Tags

Risk: Breaks themes (custom)

Risk: Major rearchitecting (custom)

Type: Security (custom)

Type: Standards compliance (custom)

Handling member Chris Graham
Addon core
Description A new spec is currently in development:

https://dvcs.w3.org/hg/content-security-policy/raw-file/tip/csp-specification.dev.html

It is led by Firefox, but experimental implementations are in IE10 and Chrome. Safari and Opera do not have anything yet.
Steps to reproduce

Additional information This will be a lot of work to support, but has a big gain. It means we can greatly reduce the chance of XSS attack and sleep a bit easier, as XSS holes are really hard to consistently avoid (even though the ocProducts version of PHP has isolated Composr much better than other projects).

http://www.html5rocks.com/en/tutorials/security/content-security-policy/
Related to

#2005 - Web standards refresh

Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated