elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.71k stars 8.13k forks source link

Research desired CSP for serverless offering #158015

Open legrego opened 1 year ago

legrego commented 1 year ago

We should audit the available CSP options against our current policy, and identify which, if any, we should consider adding/altering to the serverless offering. If these changes don't break the classic offering, then they should be applied there, too.

The output of this issue is:

The initial and ideal CSP may be identical, and that is fine. The purpose of this task is to understand the available options, and which of them are applicable to Kibana.

elasticmachine commented 1 year ago

Pinging @elastic/kibana-security (Team:Security)

legrego commented 1 year ago

Blocked on https://github.com/elastic/kibana/issues/153584