firefox-devtools / profiler-server

Firefox Profiler server and data storage infrastructure
Mozilla Public License 2.0
17 stars 11 forks source link

Security Checklist from Firefox Security Operations #18

Open arroway opened 4 years ago

arroway commented 4 years ago

Risk Management

Infrastructure

Development

Dual Sign Off

Logging

Web Applications

Security Features

Databases

Common issues

julienw commented 4 years ago

I did run of our staging server on Mozilla Observatory and ssltest, I found the following issues:

julienw commented 4 years ago

They report that some CSP properties are missing, but I see them. So maybe we don't specify them properly. I'll look into that.

I think this happens because we don't specify them on error. I'll fix that.

julienw commented 4 years ago

Here are the hosting-related concerns, that I'll check with the hosting team:

Added problem on May 13 after running api.profiler.firefox.com through mozilla observatory: