Skip to content

Conversation

@drwetter
Copy link
Contributor

@drwetter drwetter commented Dec 6, 2024

  • CSP sounded too promising and easy going to me. Also the frame-ancestor option is worth to mention explicitly
  • HSTS was amended using the term browser right in the beginning and added max-age in the description.

For the term browser: maybe we should mention some place else that this tab is for browsers only. I've seen folks believing that e.g. non-browser API clients honor HSTS instead of switching off clear text HTTP on the server side.

@drwetter drwetter requested a review from riramar as a code owner December 6, 2024 12:55
@righettod
Copy link
Member

righettod commented Dec 6, 2024 via email

@riramar riramar requested a review from righettod December 6, 2024 13:41
Copy link
Member

@righettod righettod left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very nice enhancements. Thanks a lot @drwetter 👍
I validated the PR, @riramar you can merge it when you want 💯
@drwetter / @riramar Once it will be me merged, I will add the suggestion from Dirk about explicitly mentioning that specified headers are for browsers.

@righettod righettod self-assigned this Dec 9, 2024
@riramar riramar merged commit 4da334f into OWASP:master Dec 9, 2024
@righettod
Copy link
Member

Very nice enhancements. Thanks a lot @drwetter 👍 I validated the PR, @riramar you can merge it when you want 💯 @drwetter / @riramar Once it will be me merged, I will add the suggestion from Dirk about explicitly mentioning that specified headers are for browsers.

Suggestion proposed in PR #198

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants