No Content Security Policy headers
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- typescript
Research direction
Start by locating the SvelteKit hook where response headers can be set; the issue does not name a file or test. Define a strict CSP appropriate for the app, add the header there once the app is stable, and verify that responses include it without breaking the application.
Written by the indexing model from the issue text.
Description
No CSP headers are set anywhere. This leaves the app exposed to XSS in ways that a strict CSP would mitigate. Should be added in a SvelteKit hook once the app stabilises.
- Dominant language
- TypeScript
- Stars
- 1
- Forks
- 0
- Avg merge
- 22h 6m
- Merged PRs (30d)
- 12
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from stackabletech/cockpit
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
stackabletech/cockpit#312 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
stackabletech/cockpit#224 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
stackabletech/cockpit#101 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
stackabletech/cockpit#313 ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
stackabletech/cockpit#310 ·
All issues in stackabletech/cockpit
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
bug v2
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
modelcontextprotocol/inspector#2458 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
carbon-design-system/ibm-products#9907 ·