View Issue Details

IDProjectCategoryView StatusLast Update
5865Composrcorepublic2024-08-13 01:13
ReporterGuest Assigned ToPDStig  
PriorityhighSeverityminor 
Status closedResolutionduplicate 
Product Version11.alpha4 
Summary5865: Forms specifying a redirect in the action are blocked by CSP
DescriptionAny forms which specify a redirect as part of its action (such as block top login) could get blocked by Content Security Policy in Chrome and Safari due to tightened security.

We should work around this by doing an internal redirect via a redirect POST parameter.
TagsNo tags attached.
Attach Tags
Time estimation (hours)
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Relationships

duplicate of 5770 Not AssignedGuest Forms specifying a redirect in the action are blocked by CSP 

Activities

admin

2024-05-19 20:43

administrator   ~9149

Automated message: This issue was created using the Report Issue Wizard on the Composr homesite.

Chris Graham

2024-07-25 22:35

administrator   ~9150

protect_url_parameter is supposed to be used. Also modify the function comment for protect_url_parameter, _protect_url_parameter, and comment in global2.php against INPUT_FILTER_MODSECURITY_URL_PARAMETER, to also mention browser reflected-XSS filtering.

PDStig

2024-08-13 01:12

administrator   ~9172

Last edited: 2024-08-13 01:13

This is a spam copy/paste submission; exact copy of 5770.

Issue History

Date Modified Username Field Change
2024-08-09 08:12 Guest New Issue
2024-08-09 08:12 Guest Issue generated from: 5770
2024-08-13 01:12 PDStig Assigned To => user4172
2024-08-13 01:12 PDStig Status Not Assigned => Closed
2024-08-13 01:12 PDStig Resolution open => duplicate
2024-08-13 01:12 PDStig Note Added: 0009172
2024-08-13 01:12 PDStig Relationship replaced duplicate of 5853
2024-08-13 01:12 PDStig Relationship added duplicate of 5770
2024-08-13 01:13 PDStig Note Edited: 0009172
2024-08-13 01:13 PDStig Relationship deleted 5853