Details
-
Type: Improvement
-
Status: Closed
-
Priority: Major
-
Resolution: Won't Fix
-
Affects Version/s: None
-
Fix Version/s: EE-4.3.0.GA_P04, EE-3.3.0.GA_P10
-
Component/s: Framework
-
Labels:None
-
Environment:ICEfaces EE
-
Support Case References:
-
Affects:Compatibility/Configuration
Description
We have a customer who is trying to implement a Content-Security-Policy (CSP) Level 2 for their ICEfaces applications.
We should research the requirements for this and document what resources ICEfaces itself requires to be included as a first step, with potentially including a Level 2 CSP filter in future ICEfaces releases if that is appropriate and feasible.
We should research the requirements for this and document what resources ICEfaces itself requires to be included as a first step, with potentially including a Level 2 CSP filter in future ICEfaces releases if that is appropriate and feasible.
Activity
- All
- Comments
- History
- Activity
- Remote Attachments
- Subversion
The research for CSP level 2 support in ICEfaces shows that the core and its components are fundamentally not suited for a strict CSP implementation. There are various reasons which are described below:
Although CSP level 2 support is not possible ICEfaces uses alternative mechanisms to combat XSS (Cross-site Scripting):