Project

General

Profile

Actions

Bug #100621

closed

Epic #87417: Integrate proper Content Security Policy (CSP) handling

CSP: Reduce a directive by a URL in csp.yaml is not working

Added by Chris Müller over 1 year ago. Updated 5 months ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
Start date:
2023-04-16
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
12
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Given the following snippet in a csp.yaml:

inheritDefault: true
mutations:
  - mode: reduce
    directive: 'frame-src'
    sources:
      - "*.vimeo.com" 

This should remove the default source "*.vimeo.com", but it does not.

The problem seems to lie in the SourceCollection->without() method: Here two UriValue objects are compared via in_array which returns false (and negate to true). So the source is kept.


Related issues 1 (1 open0 closed)

Related to TYPO3 Core - Feature #99499: Introduce Content Security Policy handlingUnder ReviewOliver Hader2023-03-01

Actions
Actions

Also available in: Atom PDF