-
Notifications
You must be signed in to change notification settings - Fork 41
Security: Implement Content Security Policy (CSP) Headers #179
Copy link
Copy link
Open
Labels
assignedIndicates that the issue has been assigned to a contributor who is actively working on it.Indicates that the issue has been assigned to a contributor who is actively working on it.backendBackend developmentBackend developmentenhancementNew feature or requestNew feature or requesttype:backendChanges backend services or server-side logic.Changes backend services or server-side logic.type:featureIntroduces a new feature or enhancement.Introduces a new feature or enhancement.
Description
Activity
Metadata
Metadata
Assignees
Labels
assignedIndicates that the issue has been assigned to a contributor who is actively working on it.Indicates that the issue has been assigned to a contributor who is actively working on it.backendBackend developmentBackend developmentenhancementNew feature or requestNew feature or requesttype:backendChanges backend services or server-side logic.Changes backend services or server-side logic.type:featureIntroduces a new feature or enhancement.Introduces a new feature or enhancement.
What the issue is & The core problem
The application lacks strict CSP headers, leaving it vulnerable to Cross-Site Scripting (XSS) if third-party dependencies are compromised.
Specific files to be changed
index.htmlvite.config.tsDetailed proposed solution
Configure the Vite build or the backend hosting provider to inject strict
Content-Security-PolicyHTTP headers, restrictingscript-srcandconnect-srcto known domains.Impact/Effect on the project
Provides a robust defense-in-depth layer against malicious script execution.
Benefits to the maintainers/users
Ensures user sessions and local storage data remain secure against XSS exfiltration.
Assignment Request
Hey maintainers, I would like to work on this issue. Could you please assign it to me and add the
ECSoC26,Level 3, andgood-backendlabels?Program: ECSoC'26