Project

General

Profile

Actions

Feature #87423

closed

Epic #87417: Integrate proper Content Security Policy (CSP) handling

Integrate CSP management module

Added by Oliver Hader over 5 years ago. Updated 3 months ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Backend User Interface
Target version:
Start date:
2019-01-13
Due date:
% Done:

100%

Estimated time:
PHP Version:
Tags:
Complexity:
Sprint Focus:

Description

In oder to grant access, configure behavior and monitor configuration flaws or violations (e.g. of 3rd party extensions) a content security policy management module shall be integrated.

  • grant/revoke access (based on manifest)
  • configure content security level (predefined/presets)
  • log of recent violations with UI filter capabilities (search for URI, type, date/time, ...)

Test-Extension


DRAFT CSP rules

DRAFT CSP reports


Files

mockup_Rules.png (80.4 KB) mockup_Rules.png DRAFT CSP rules Oliver Hader, 2021-05-06 17:52
mockup_Reports.png (89.3 KB) mockup_Reports.png DRAFT CSP reports Oliver Hader, 2021-05-06 17:52
typo3_csp.bmpr (100 KB) typo3_csp.bmpr Balsamiq mockup Oliver Hader, 2021-05-06 17:52

Related issues 5 (2 open3 closed)

Related to TYPO3 Core - Feature #87421: Integrate CSP reporting endpointClosed2019-01-13

Actions
Related to TYPO3 Core - Task #100535: CSP module: On small browser size the UX of the details view could be improvedAccepted2023-04-08

Actions
Related to TYPO3 Core - Task #100616: Add docheader buttons to CSP moduleUnder ReviewChris Müller2023-04-16

Actions
Related to TYPO3 Core - Bug #100618: CSP module: Mute and delete of violations do not workResolved2023-04-16

Actions
Has duplicate TYPO3 Core - Feature #100056: Introduce Content Security Policy reporting & inspectionClosed2023-03-01

Actions
Actions

Also available in: Atom PDF