Success

User tests: Successful: Unsuccessful:

avatar zero-24
zero-24
4 Feb 2018

Summary of Changes

With this PR we set the basic http security headers

Open points / questions

  • CSP rules (needs to wait until we have a csp-reporter place)
avatar zero-24 zero-24 - open - 4 Feb 2018
avatar mbabker
mbabker - comment - 4 Feb 2018

Umm, this isn't the help proxy, and I'm not aware of anyone iframing the issue tracker into a site ?

avatar Hutchy68
Hutchy68 - comment - 4 Feb 2018

Ooops, watching football previews. ? Thought it was a blanket default for all sites.

avatar mbabker
mbabker - comment - 4 Feb 2018

Well, it probably is a default, but that's why we have PR reviews and repositories for the majority of the sites. Go back to football now.

avatar Hutchy68
Hutchy68 - comment - 4 Feb 2018

? + ? == ?

avatar zero-24
zero-24 - comment - 4 Feb 2018

? Have fun with football today ?

avatar mbabker mbabker - close - 12 Feb 2018
avatar mbabker mbabker - merge - 12 Feb 2018
avatar mbabker mbabker - reference | b26718e - 12 Feb 18
avatar mbabker mbabker - merge - 12 Feb 2018
avatar mbabker mbabker - change - 12 Feb 2018
Status New Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2018-02-12 23:24:38
Closed_By mbabker
avatar mbabker mbabker - close - 12 Feb 2018
avatar zero-24 zero-24 - head_ref_deleted - 12 Feb 2018
avatar zero-24
zero-24 - comment - 12 Feb 2018

Thanks but looks like this server has also a broken mod_headers module: https://securityheaders.io/?q=https%3A%2F%2Fissues.joomla.org%2F&hide=on&followRedirects=on :(

avatar mbabker
mbabker - comment - 13 Feb 2018

developer., framework., and issues. all reside on the same server.

Add a Comment

Login with GitHub to post a comment