Skip to content

Security: Implement Content Security Policy (CSP) Headers #179

Description

@Diwakar-odds

What the issue is & The core problem

The application lacks strict CSP headers, leaving it vulnerable to Cross-Site Scripting (XSS) if third-party dependencies are compromised.

Specific files to be changed

  • index.html
  • vite.config.ts

Detailed proposed solution

Configure the Vite build or the backend hosting provider to inject strict Content-Security-Policy HTTP headers, restricting script-src and connect-src to known domains.

Impact/Effect on the project

Provides a robust defense-in-depth layer against malicious script execution.

Benefits to the maintainers/users

Ensures user sessions and local storage data remain secure against XSS exfiltration.

Assignment Request
Hey maintainers, I would like to work on this issue. Could you please assign it to me and add the ECSoC26, Level 3, and good-backend labels?
Program: ECSoC'26

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

assignedIndicates that the issue has been assigned to a contributor who is actively working on it.backendBackend developmentenhancementNew feature or requesttype:backendChanges backend services or server-side logic.type:featureIntroduces a new feature or enhancement.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions