OWASP / www-project-secure-headers

The OWASP Secure Headers Project
https://owasp.org/www-project-secure-headers/
Apache License 2.0
138 stars 38 forks source link

Add CORS section #160

Closed righettod closed 1 year ago

righettod commented 1 year ago

Hi,

This PR add a new section, in the Best Practices tab, regarding the configuration of the CORS headers .

🤝 @riramar I need your help to review my proposal and ensure that my content is accurate, helpful and does not any technical mistake.

📋 It is a work on this issue.

Thank you a lot for your help 👍

riramar commented 1 year ago

Hi @righettod

Thanks for sending this PR. CORS for sure it's something we need to improve in our OWASP project. I'm on vacation right now, so I'll review your PR probably during next week. Meanwhile I'd recommend you to check the posts about CORS from here https://jub0bs.com/posts/. Julien Cretel has provided amazing content regarding CORS security.

Best regards, Ricardo Iramar

righettod commented 1 year ago

Hi @riramar ,

Take the time you need and do it when you have spare time for it. I will take a close look at the site your mentioned to see what content I can get.

Enjoy your vacation 😃

riramar commented 1 year ago

Thanks @righettod !

righettod commented 1 year ago

You are welcome, thanks a lot for your review 👍