Project

General

Profile

Actions

Bug #103939

closed

Allow using CSPs without Nonce-feature

Added by Patrick Schriner 6 months ago. Updated 6 months ago.

Status:
Rejected
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2024-05-28
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
12
PHP Version:
Tags:
Complexity:
easy
Is Regression:
Sprint Focus:

Description

It should be possible to write a middleware that adds frontend CSPs without nonces being required.

Forcing nonce usage has a serious performance implication as in fact every request has to be partially uncached


Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Bug #103942: nonce is rendered to the CSP Header although nonce has not been consumedClosedBenjamin Franzke2024-05-28

Actions
Actions #1

Updated by Patrick Schriner 6 months ago

  • Description updated (diff)
Actions #2

Updated by Gerrit Code Review 6 months ago

  • Status changed from New to Under Review

Patch set 1 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/84433

Actions #3

Updated by Gerrit Code Review 6 months ago

Patch set 2 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/84433

Actions #4

Updated by Benjamin Franzke 6 months ago

  • Related to Bug #103942: nonce is rendered to the CSP Header although nonce has not been consumed added
Actions #5

Updated by Gerrit Code Review 6 months ago

Patch set 3 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/84433

Actions #6

Updated by Gerrit Code Review 6 months ago

Patch set 4 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/84433

Actions #7

Updated by Gerrit Code Review 6 months ago

Patch set 5 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/84433

Actions #8

Updated by Benjamin Franzke 6 months ago

  • Status changed from Under Review to Rejected

Should be fixed via #103942.

Actions

Also available in: Atom PDF