Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider implementing CSP headers on our HTTP UI Server #12553

Open
johncowen opened this issue Jan 14, 2025 · 1 comment
Open

Consider implementing CSP headers on our HTTP UI Server #12553

johncowen opened this issue Jan 14, 2025 · 1 comment
Labels
kind/feature New feature triage/accepted The issue was reviewed and is complete enough to start working on it

Comments

@johncowen
Copy link
Contributor

Description

See https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP

Discuss with frontend which policies we can apply.

@johncowen johncowen added kind/feature New feature triage/pending This issue will be looked at on the next triage meeting labels Jan 14, 2025
@lukidzi lukidzi added triage/accepted The issue was reviewed and is complete enough to start working on it and removed triage/pending This issue will be looked at on the next triage meeting labels Jan 20, 2025
@johncowen
Copy link
Contributor Author

Just wanted to note on here, that we could also just document which CSP headers are needed, not necessarily always add them.

(I'm guessing we already have the ability to add headers to the guis responses?)

johncowen added a commit to kumahq/kuma-gui that referenced this issue Feb 20, 2025
Adds stricter CSP headers to our development vite server.

Whilst this is dev time only, it ensures that our GUI runs on a
similarly configured server (such as
kumahq/kuma#12553)

---

As mentioned in other places, it would be good to add work so we can
remove the `style-src 'unsafe-inline'`. This will require a globally
available `v-style` directive which adds/removes/modifies styles
imperatively behind the scenes.

Testing:

Using `make run`, add the following or similar anchor with an inline
script and click it.

<img width="1719" alt="Untitled-1"
src="https://github.com/user-attachments/assets/8d493851-9a92-45fe-95e6-b67ea4606a5c"
/>

---------

Signed-off-by: John Cowen <john.cowen@konghq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature New feature triage/accepted The issue was reviewed and is complete enough to start working on it
Projects
None yet
Development

No branches or pull requests

2 participants