Displaying 1 - 26 of 26
Title Status Priority Category Version Component Replies Last updatedsort ascending Assigned to Created
Lottie files / base64 encoding Active Normal Support request 7.x-1.11 Miscellaneous 2 2 years 8 months 3 years 6 months
Allow report only and block policies simultaneously Active Normal Support request 7.x-1.x-dev Code 6 4 years 7 months 7 years 2 months
Deprecate the policy-uri CSP directive, as it is no longer in the spec Active Major Task 7.x-1.x-dev Code 14 4 years 8 months 10 years 6 months
Improve help, recommendations for CSP options Needs review Normal Feature request 7.x-1.x-dev User interface 14 4 years 8 months 9 years 8 months
Recommend some external documentation for SecKit to link to Active Normal Task 7.x-1.x-dev Documentation 9 4 years 8 months 11 years 5 months
Field for Cross Site Forgery origin whitelist is too small. Needs work Normal Feature request 7.x-1.9 Miscellaneous 8 5 years 3 months 10 years 6 months
Automatically generated nonce for inline scripts Active Normal Feature request 7.x-1.11 Code 4 5 years 4 months 6 years 10 months
JavaScript + CSS + Noscript protection still valid? Needs work Major Bug report 7.x-1.x-dev Code 19 5 years 9 months 10 years 9 months
CSP form-action directive Needs review Major Task 7.x-1.x-dev Code 6 7 years 11 months 7 years 11 months
SyntaxError: missing } after function body Active Normal Bug report 7.x-1.9 Code 3 8 years 1 month 8 years 1 month
Separate headers for /admin area Active Normal Feature request 7.x-1.9 Code 1 8 years 1 month 8 years 1 month
Firefox Issues with X-Frame-Options Active Normal Support request 7.x-1.x-dev Code 4 8 years 2 months 8 years 2 months
Fallback for $_SERVER['HTTP_ORIGIN'] used in seckit_boot() Needs review Normal Feature request 7.x-1.x-dev Code 12 8 years 8 months 11 years 3 weeks
Improve the documentation for X-Frame-Options "Allow-From" Active Normal Task 7.x-1.9 Code 5 8 years 8 months 10 years 11 months
More clearly explain which CSP options allow 'unsafe-inline' or 'unsafe-eval' Active Normal Bug report 7.x-1.x-dev Documentation 3 9 years 2 months 9 years 8 months
"Enable JavaScript + CSS + Noscript protection" is not compatible with IE10 Needs work Normal Bug report 7.x-1.9 Code 13 9 years 4 months 11 years 10 months
Alter JS in SecKit to convert Drupal.settings to JSON Needs work Normal Feature request 7.x-1.x-dev Code 5 9 years 6 months 11 years 1 month
Exclude SecKit protection from LABjs Needs review Normal Bug report 7.x-1.x-dev Code 10 9 years 8 months 10 years 10 months
Replace seckit.listener.js with Form API #states Active Normal Task 7.x-1.x-dev Code 1 10 years 3 months 11 years 2 months
Use States API on required fields in the configuration form. Active Minor Task 7.x-1.x-dev User interface 10 10 years 3 months 10 years 5 months
Enable the random padding of HTTPS responses for authenticated users to mitigate BREACH attacks Active Normal Feature request 7.x-1.x-dev Code 8 10 years 4 months 10 years 4 months
Declare variables in hook_variable_info Postponed (maintainer needs more info) Normal Task 7.x-1.x-dev Code 8 10 years 7 months 10 years 11 months
Establish the correct behaviour when Origin = 'null' Needs review Normal Task 7.x-1.x-dev Code 3 10 years 7 months 10 years 7 months
In _seckit_origin(), refer to rfc6454 Postponed (maintainer needs more info) Normal Task 7.x-1.x-dev Documentation 3 10 years 7 months 11 years 8 months
Allowing per-page overrides for Security Kit settings Postponed Minor Feature request 7.x-1.9 Miscellaneous 5 11 years 2 months 12 years 2 months
Just a warning about CSP Active Normal Task 7.x-1.x-dev Miscellaneous 12 years 2 months 12 years 2 months
Subscribe with RSS Subscribe to Issues for Security Kit