Make autoCSP configurable
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- angular, typescript
- Lĩnh vực
- build-system, security
Hướng nghiên cứu
Bắt đầu với lệnh build của CLI và đường dẫn tạo autoCSP hiện có. Theo dõi cách Content-Security-Policy được tạo ra được lắp ráp, sau đó xác minh rằng các chỉ thị được yêu cầu có thể được cấu hình và chính sách kết quả hoạt động với các trường hợp nginx và PWA đã nêu.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Command
build
Description
Great to see autoCSP property cause looks like it's the only way to go with PWA.
Please could you make possible to add extra options to generated CSP ? I'd love to specify for example default-src, img-src e.t.c.
Describe the solution you'd like
Make it somehow configurable:
"autoCsp": {
"default-src": "'self'",
"img-src": "* data: blob:",
"media-src": "'self' data:"
}
Describe alternatives you've considered
A header still will be needed for frame-ancestors to add (for example in nginx):
add_header Content-Security-Policy "frame-ancestors 'none'";
It works nicely in conjuction with autoCSP and I can even specify
add_header Content-Security-Policy "frame-ancestors 'none'; media-src 'self' data:";
The issue here is that if I add default-src
add_header Content-Security-Policy "default-src 'self'; frame-ancestors 'none'; media-src 'self' data:";
Angular app will be broken because the least permissive policy (this one) wins.
To workaround it I will have to specify each case separately here worker-src; frame-src e.t.c but do not specify script-src which will make it enormous and hard to maintain.
I would love to specify them in index.html directly
- Ngôn ngữ chính
- TypeScript
- Star
- 27k
- Fork
- 11.8k
- Merge trung bình
- 16 giờ 35 phút
- Pull request đã merge (30 ngày)
- 176
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của angular/angular-cli
-
Can't use an array of hostnames in --allowedHosts cli parameter in @angular/build:dev-server Đang mởarea: @angular/build gemini-triaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
angular/angular-cli#33955 ·
-
area: @angular/cli gemini-triaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
angular/angular-cli#33055 · 1 bình luận · 3 reaction ·
-
unit-test: with --coverage, a setup file's hooks reach only the first spec file of each worker Đang mởarea: @angular/build gemini-triaged
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 72/100
angular/angular-cli#34137 ·
-
angular/build:library area: @angular/build gemini-triaged
angular/angular-cli#34131 · 1 người được giao ·
-
angular/build:library area: @angular/build gemini-triaged
angular/angular-cli#34130 · 1 người được giao ·
Tất cả issue của angular/angular-cli
Issue tương tự
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
dennys-bd/agent-hive#184 ·
-
Add: hunch Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
AbdelStark/awesome-typesafe#104 ·
-
ai-observability bug team/ai-observability
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
vicharanashala/fln#563 ·