View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0021908 | mantisbt | security | public | 2016-11-13 06:45 | 2023-09-14 03:25 |
Reporter | atrol | Assigned To | |||
Priority | normal | Severity | minor | Reproducibility | always |
Status | confirmed | Resolution | open | ||
Target Version | 2.26.0 | ||||
Summary | 0021908: Weakened security headers in 2.0.x | ||||
Description | 2.0.x comes with http_csp_add( 'style-src', "'unsafe-inline'" ); in http_api.php. | ||||
Tags | csp | ||||
Why you don't allow unsafe-inline styles in 1.3.x. ? |
|
Wrong question, it should be: Why you allow unsafe-inline styles in 2.x? Allowing unsafe-inline styles decreases security. |
|
@yanual I suggested you read https://stackoverflow.com/a/31759553/1045774 for a brief explanation of the potential risks to your site when unsafe-inline styles are allowed. |
|
@atrol your formulation is indeed better. |
|