|
Lottie files / base64 encoding |
Active |
Normal |
Support request |
7.x-1.11 |
Miscellaneous |
|
3 years 6 months |
|
Allow report only and block policies simultaneously |
Active |
Normal |
Support request |
7.x-1.x-dev |
Code |
|
7 years 2 months |
|
Deprecate the policy-uri CSP directive, as it is no longer in the spec |
Active |
Major |
Task |
7.x-1.x-dev |
Code |
|
10 years 6 months |
|
Improve help, recommendations for CSP options |
Needs review |
Normal |
Feature request |
7.x-1.x-dev |
User interface |
|
9 years 8 months |
|
Recommend some external documentation for SecKit to link to |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
11 years 5 months |
|
Field for Cross Site Forgery origin whitelist is too small. |
Needs work |
Normal |
Feature request |
7.x-1.9 |
Miscellaneous |
|
10 years 6 months |
|
Automatically generated nonce for inline scripts |
Active |
Normal |
Feature request |
7.x-1.11 |
Code |
|
6 years 10 months |
|
JavaScript + CSS + Noscript protection still valid? |
Needs work |
Major |
Bug report |
7.x-1.x-dev |
Code |
|
10 years 9 months |
|
CSP form-action directive |
Needs review |
Major |
Task |
7.x-1.x-dev |
Code |
|
7 years 11 months |
|
SyntaxError: missing } after function body |
Active |
Normal |
Bug report |
7.x-1.9 |
Code |
|
8 years 1 month |
|
Separate headers for /admin area |
Active |
Normal |
Feature request |
7.x-1.9 |
Code |
|
8 years 1 month |
|
Firefox Issues with X-Frame-Options |
Active |
Normal |
Support request |
7.x-1.x-dev |
Code |
|
8 years 2 months |
|
Fallback for $_SERVER['HTTP_ORIGIN'] used in seckit_boot() |
Needs review |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
11 years 3 weeks |
|
Improve the documentation for X-Frame-Options "Allow-From" |
Active |
Normal |
Task |
7.x-1.9 |
Code |
|
10 years 11 months |
|
More clearly explain which CSP options allow 'unsafe-inline' or 'unsafe-eval' |
Active |
Normal |
Bug report |
7.x-1.x-dev |
Documentation |
|
9 years 8 months |
|
"Enable JavaScript + CSS + Noscript protection" is not compatible with IE10 |
Needs work |
Normal |
Bug report |
7.x-1.9 |
Code |
|
11 years 10 months |
|
Alter JS in SecKit to convert Drupal.settings to JSON |
Needs work |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
11 years 1 month |
|
Exclude SecKit protection from LABjs |
Needs review |
Normal |
Bug report |
7.x-1.x-dev |
Code |
|
10 years 10 months |
|
Replace seckit.listener.js with Form API #states |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
11 years 2 months |
|
Use States API on required fields in the configuration form. |
Active |
Minor |
Task |
7.x-1.x-dev |
User interface |
|
10 years 5 months |
|
Enable the random padding of HTTPS responses for authenticated users to mitigate BREACH attacks |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
10 years 4 months |
|
Declare variables in hook_variable_info |
Postponed (maintainer needs more info) |
Normal |
Task |
7.x-1.x-dev |
Code |
|
10 years 11 months |
|
Establish the correct behaviour when Origin = 'null' |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
10 years 7 months |
|
In _seckit_origin(), refer to rfc6454 |
Postponed (maintainer needs more info) |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
11 years 8 months |
|
Allowing per-page overrides for Security Kit settings |
Postponed |
Minor |
Feature request |
7.x-1.9 |
Miscellaneous |
|
12 years 2 months |
|
Just a warning about CSP |
Active |
Normal |
Task |
7.x-1.x-dev |
Miscellaneous |
|
12 years 2 months |