Add a CSP policy that only allows loading resources from Toolhub itself and upload.wikimedia.org. Lock this down as tight as we can for initial launch.
Description
Description
Details
Details
Related Changes in Gerrit:
| Subject | Repo | Branch | Lines +/- | |
|---|---|---|---|---|
| backend: Add Content-Security-Policy header and report collector | wikimedia/toolhub | main | +147 -3 |
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Open | None | T288685 Establish active/active multi-dc support for Toolhub | |||
| Resolved | bd808 | T115650 Create an authoritative and well promoted catalog of Wikimedia tools | |||
| Resolved | bd808 | T271483 Complete and announce initial production deployment of Toolhub | |||
| Resolved | bd808 | T278882 Add Content-Security policy config |
Event Timeline
Comment Actions
Change 704641 had a related patch set uploaded (by BryanDavis; author: Bryan Davis):
[wikimedia/toolhub@main] backend: Add Content-Security-Policy header and report collector
Comment Actions
Change 704641 merged by jenkins-bot:
[wikimedia/toolhub@main] backend: Add Content-Security-Policy header and report collector