ElixirTeSS / TeSS

Training e-Support Service using Ruby on Rails.
Other
12 stars 14 forks source link

XSS defense: Content-Security-Policy & Permissions-Policy / Feature-Policy #865

Open DaanVanVugt opened 1 year ago

DaanVanVugt commented 1 year ago

Is your feature request related to a problem? Please describe Given that there is a lot of user-generated and scraped content, it may be prudent to limit accessible content and browser features. We get a relatively low grade at https://securityheaders.com/?q=https%3A%2F%2Ftess.elixir-europe.org&followRedirects=on

Describe the solution you'd like

Implement a Content-Security-Policy and perhaps also a Feature-Policy