Page MenuHomePhabricator

Give MW a .htaccess in the images directory to mirror Wikimedia's CSP settings
Closed, ResolvedPublic

Description

Would be a good hardening step for people using MW with apache who have .htaccess enabled, once we have enabled our CSP and verified that it works well.

Event Timeline

Change 547930 had a related patch set uploaded (by Brian Wolff; owner: Brian Wolff):
[mediawiki/core@master] [DNM] Set a CSP header to sandbox uploaded files

https://gerrit.wikimedia.org/r/547930

Change #547930 merged by jenkins-bot:

[mediawiki/core@master] Set a CSP header to sandbox uploaded files

https://gerrit.wikimedia.org/r/547930

TheDJ subscribed.

It seems it forgot to add the right version numbers to the php comments. Will fix later today.

Change #1177458 had a related patch set uploaded (by TheDJ; author: TheDJ):

[mediawiki/core@master] Fix @since for CSPUploadEntryPoint

https://gerrit.wikimedia.org/r/1177458

Change #1177458 merged by jenkins-bot:

[mediawiki/core@master] Fix @since for CSPUploadEntryPoint

https://gerrit.wikimedia.org/r/1177458

A_smart_kitten subscribed.

Optimistically re-resolving now that the follow-up patch has been merged :)