Skip to content

nginx/csp: backend "pages" should be 100% locked down #1516

@alxndrsn

Description

@alxndrsn

For any paths which are not expected to be loaded as the main browser document, any CSP header served should lock down 100%.

Confirm if there are paths which are expected to be loaded as the main browser document (e.g. #1478, potentially other OIDC paths).

I think this is OK:

  • /oidc/callback has special handling
  • /oidc/login should always send a redirect rather than rendering content

Metadata

Metadata

Assignees

Labels

opsDocker, nginx, ops to deploy Central

Type

No type

Projects

Status

✅ done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions