google / csp-evaluator

https://csp-evaluator.withgoogle.com
Apache License 2.0
327 stars 46 forks source link

Claims that allowing requests to http://127.0.0.1 is a risk #5

Closed BenjaminEHowe closed 4 years ago

BenjaminEHowe commented 6 years ago

I don't think I need HTTPS when requests will stay within my computer. w3c agrees, considering http://127.0.0.1 "potentially trustworthy", and therefore most modern browsers wouldn't warn of mixed content. Please could this tool be tweaked?

lweichselbaum commented 4 years ago

I'm closing this as working as intended. Loopback addresses shouldn't be used in an production environment.