OWASP / wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
https://owasp.org/www-project-web-security-testing-guide/
Creative Commons Attribution Share Alike 4.0 International
7.19k stars 1.32k forks source link

Add a test for Content Security Policy headers #654

Open phish opened 3 years ago

phish commented 3 years ago

I haven't found any test that includes looking at the Content Security Headers. I would expect this to be included either in

Typically, we should check for unsafe-eval and other potentially dangerous settings.

ThunderSon commented 3 years ago

I believe this fits in the CONF chapter, and bypasses can link to it in the CLNT chapter.

Would love to add this in!

Are you interested to propose a plan for this addition?

phish commented 3 years ago

I wont be able to work on this before the end of the year. If nothing has been done by then, I'll be happy to contribute.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

phish commented 3 years ago

I've finished the document, I'll be posting a pull request soon.

DotDotSlashRepo commented 3 years ago

Oopsie! I did a PR #708 earlier on this.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.