Throw deprecation warning if directive contains 'none' and other values

Created on 24 December 2023, 6 months ago
Updated 14 January 2024, 5 months ago

Problem/Motivation

To prepare for changing the behaviour of handing 'none' in a directive's values in CSP 2.0, reduceSourceList() should throw a deprecation warning if a directive contains 'none' alongside other sources (except valid keywords like 'report-sample')

Steps to reproduce

Proposed resolution

If a directive contains 'none' alongside other sources (domains, protocols, 'unsafe-inline', etc), throw a deprecation warning that a site should remove any undesired sources.

Remaining tasks

User interface changes

API changes

Data model changes

πŸ“Œ Task
Status

Fixed

Version

1.0

Component

Code

Created by

πŸ‡¨πŸ‡¦Canada gapple

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.69.0 2024