|
Implement a "semi automatic" Nonce settings |
Needs review |
Normal |
Feature request |
2.x-dev |
Miscellaneous |
|
4 years 6 months |
|
Add form-action directive |
Reviewed & tested by the community |
Normal |
Feature request |
2.x-dev |
Code |
|
4 years 11 months |
|
Add Tugboat support |
Needs review |
Normal |
Task |
2.x-dev |
Code |
|
1 month 6 days |
|
[META] Roadmap to new release |
Active |
Normal |
Feature request |
2.x-dev |
Code |
|
1 month 1 week |
|
fix gaps in automated test coverage |
Needs review |
Normal |
Task |
2.0.3 |
Code |
|
1 month 2 weeks |
|
Add missing config schema definitions for X-XSS-Protection options in Seckit |
Reviewed & tested by the community |
Normal |
Bug report |
2.0.3 |
Code |
|
4 months 3 weeks |
|
Support for configuring script-src-elem |
Active |
Normal |
Feature request |
2.x-dev |
Code |
|
1 year 1 month |
|
Add worker-src |
Needs review |
Normal |
Feature request |
2.0.3 |
Code |
|
2 years 1 month |
|
ALLOW-FROM directive in x-frame-options is obsolete |
Active |
Normal |
Bug report |
2.0.0 |
Code |
|
3 years 5 months |
|
Add Permissions Policy to configurable options |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
5 years 5 months |
|
Add support for the Cross-Origin-Opener-Policy (COOP) header |
Reviewed & tested by the community |
Normal |
Feature request |
2.x-dev |
Code |
|
9 months 4 weeks |
|
Remove the term whitelist* from the module |
Needs review |
Normal |
Task |
2.0.3 |
Code |
|
9 months 3 days |
|
Add trusted-type and require-trusted-type-for directives to the CSP |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
3 months 1 week |
|
Support flood control for CSP violation reports |
Needs work |
Major |
Task |
8.x-1.x-dev |
Code |
kmoll |
10 years 1 month |
|
Enabling "Enable JavaScript + CSS + Noscript protection" causes invalid HTML |
Needs work |
Normal |
Bug report |
2.x-dev |
Code |
|
6 years 10 months |
|
noscript in head tag causing HTML Validation issues |
Active |
Major |
Bug report |
2.0.0 |
Code |
|
3 years 11 months |
|
report-uri is deprecated |
Needs work |
Normal |
Bug report |
2.x-dev |
Code |
|
3 years 2 weeks |
|
Add manifest-src |
Needs work |
Normal |
Feature request |
2.0.0 |
Code |
|
5 years 1 month |
|
The base-uri policy is missing |
Needs review |
Normal |
Bug report |
2.x-dev |
Code |
|
6 years 5 months |
|
text about drupal 6 |
Active |
Minor |
Bug report |
2.0.3 |
Documentation |
|
5 months 3 weeks |
|
Update CSP directives |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
8 years 7 months |
|
JavaScript + CSS + Noscript protection can cause Javascript errors |
Active |
Normal |
Bug report |
2.x-dev |
Code |
|
7 months 3 hours |
|
CSP: Directive script-src-elem violated with googletagmanager |
Reviewed & tested by the community |
Normal |
Support request |
2.x-dev |
Code |
|
5 years 4 weeks |
|
cspell issues reported in pipeline |
Active |
Normal |
Task |
2.x-dev |
Code |
|
9 months 3 weeks |
|
Implement the script-src-attr policy |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
4 years 1 month |
|
Breaks sitemap.xml when JS +CSS + Noscript protection is enabled |
Needs review |
Normal |
Bug report |
2.0.0 |
Code |
|
4 years 11 months |
|
User interface improvements |
Active |
Minor |
Feature request |
2.0.3 |
User interface |
|
1 year 2 days |
|
Extend length of src fields |
Needs review |
Major |
Feature request |
2.0.0 |
Code |
|
5 years 1 month |
|
default-src has wrong description |
Needs review |
Major |
Bug report |
2.x-dev |
Documentation |
|
5 years 3 months |
|
Avoid using document.write('<!--'); |
Needs review |
Normal |
Task |
2.x-dev |
Code |
|
5 years 3 months |
|
How to add all google tlds for CSP |
Active |
Normal |
Support request |
2.0.0 |
User interface |
|
3 years 11 months |
|
Google URL's are blocked. |
Active |
Major |
Support request |
2.0.1 |
Miscellaneous |
|
2 years 3 months |
|
Seckit seckitGetJsCssNoscriptCode hijacks js aggregation files. |
Needs work |
Normal |
Bug report |
2.x-dev |
Code |
|
2 years 3 weeks |
|
"Directive style-src-elem violated." |
Needs review |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
5 years 8 months |
|
Allow certain paths to be excluded from the Origin check (patch included) |
Needs review |
Normal |
Feature request |
2.0.0 |
Code |
|
5 years 2 months |
|
Add worker-src |
Reviewed & tested by the community |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
3 years 9 months |
|
Dispatch an event when there is a CSP violation |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
1 year 5 months |
|
Missing container invalidation update from issue modifying services |
Active |
Normal |
Bug report |
2.x-dev |
Code |
|
1 year 8 months |
|
Clickjacking CSS protection hides content when site is embed inside an iframe, even if frame-ancestors is set |
Needs review |
Normal |
Bug report |
2.0.1 |
Code |
|
2 years 3 months |
|
Provide hook_seckit_options_alter() D8 |
Needs review |
Major |
Feature request |
2.0.3 |
Code |
|
9 years 3 months |
|
Update summary on project page for compatibility with Project Browser |
Active |
Normal |
Task |
2.0.3 |
Miscellaneous |
|
1 year 7 months |
|
Update logo for compatibility with Project Browser |
Active |
Normal |
Task |
2.0.3 |
Miscellaneous |
|
1 year 7 months |
|
Modernize services: Add autowiring aliases, use autoconfigure, etc |
Needs review |
Normal |
Task |
2.x-dev |
Code |
|
1 year 8 months |
|
Multiple html lines of seckitGetJsCssNoscriptCode function create issue when js aggregate and minify html is on |
Active |
Normal |
Bug report |
2.0.1 |
Code |
hetalsagar |
1 year 8 months |
|
Silent mode for CSP reporting |
Active |
Normal |
Feature request |
2.x-dev |
Code |
|
4 years 1 week |
|
Store CSP sources as a list of values on multiple lines to increase manageability and prevent merge conflicts |
Needs review |
Normal |
Feature request |
2.x-dev |
Code |
|
2 years 6 months |
|
Drupal 9.1 Deprecated Code Report |
Reviewed & tested by the community |
Normal |
Task |
2.x-dev |
Code |
sourabhjain |
5 years 4 months |
|
Question about HSTS max-age |
Active |
Normal |
Support request |
2.0.1 |
Miscellaneous |
|
2 years 1 month |
|
Add phpcs and drupal-check fixes |
Needs review |
Normal |
Task |
2.x-dev |
Code |
|
4 years 2 months |
|
t() calls should be avoided in classes. |
Needs review |
Normal |
Task |
2.0.1 |
Code |
|
2 years 2 months |