certsimple / csp-by-api

Significantly cuts down on CSP policy management by specifying common APIs by name.
17 stars 6 forks source link

Use `*` when possible #6

Closed XhmikosR closed 6 years ago

XhmikosR commented 6 years ago

It doesn't make any sense to do this for example:

"https://www.google.co.in",
"https://www.google.it",
"https://www.google.co.uk",
"https://www.google.de",
"https://www.google.fr",
"https://www.google.ca",
"https://www.google.es",
"https://www.google.com.pk",
"https://www.google.com.tw",
"https://www.google.com.ph",
"https://www.google.com.ua",
"https://www.google.co.kr",
"https://www.google.com",
"https://www.google.com.bd",
"https://www.google.com.bh",
"https://www.google.com.br",
"https://www.google.com.eg",
"https://www.google.nl",
"https://www.google.by",
"https://www.google.co.za",
"https://www.google.fi",
"https://www.google.be",
"https://www.google.co.in",
"https://www.google.com.my",
"https://www.google.ch",
"https://www.google.co.th",
"https://www.google.co.uk",
"https://www.google.cl",
"https://www.google.bg",
"https://www.google.hu",
"https://www.google.com.sa",
"https://www.google.com.sg",
"https://www.google.ie",
"https://www.google.ae",
"https://www.google.dk",
"https://www.google.cz",
"https://www.google.com.mx",
"https://www.google.com.sv",
"https://www.google.co.in",
"https://www.google.se",
"https://www.google.sk",
"https://www.google.com.ar",
"https://www.google.com.uy",
"https://www.google.co.nz",
"https://www.google.co.il",
"https://www.google.com.hk",
"https://www.google.com.vn",
"https://www.google.com.au",
"https://www.google.com.tr",
"https://www.google.co.jp",
"https://www.google.rs",
"https://www.google.ro",
"https://www.google.pl"

Clearly, you trust Google there so this is much shorter, less headers:

https://www.google.*
mikemaccana commented 6 years ago

https://www.google.fraud.ph