CSP policies should use "default-src 'none'"

Bug #1380488 reported by François Marier
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Libravatar (obsolete)
Fix Released
Medium
François Marier

Bug Description

As suggested in the CSP Level 2 spec (http://www.w3.org/TR/CSP11/#default-src-usage), we should use a "default-src 'none'" directive to disable all of the features we don't currently use (e.g. object-src, font-src and media-src).

Tags: csp
description: updated
Changed in libravatar:
status: Confirmed → Fix Committed
Changed in libravatar:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.