Misleading recommendation for CSP directive "frame-src"

Created on 19 April 2023, over 1 year ago
Updated 8 February 2024, 10 months ago

#2689277: Add ability to configure the child-src CSP directive β†’ added support for the CSP directive "child-src", and added this recommendation when editing the directive "frame-src" in the admin form:

This directive is deprecated and will be replaced by child-src. It is recommended to use the both the frame-src and child-src directives until all browsers you support recognize the child-src directive.

The preferred method is now to use "frame-src", see:

Remove the recommendation and leave the option to use both "frame-src" and "child-src" ? Both are valid: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Securi...

πŸ“Œ Task
Status

RTBC

Version

1.0

Component

Documentation

Created by

πŸ‡¨πŸ‡¦Canada fengtan Montreal, Canada

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024