Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

X-Permitted-Cross-Domain-Policies Header #8

Closed
manuel-sommer opened this issue Oct 16, 2023 · 2 comments
Closed

X-Permitted-Cross-Domain-Policies Header #8

manuel-sommer opened this issue Oct 16, 2023 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@manuel-sommer
Copy link

manuel-sommer commented Oct 16, 2023

According to OWASP Secure Headers Project , the HTTP Header X-Permitted-Cross-Domain-Policies Header should also be used. A check is mssing regarding this header.

manuel-sommer added a commit to manuel-sommer/humble that referenced this issue Oct 16, 2023
@manuel-sommer
Copy link
Author

@rfc-st I recommend you to add this project to hacktoberfest as you will then maybe receive also more PRs.

@rfc-st
Copy link
Owner

rfc-st commented Oct 20, 2023

Hello!,

Thanks for your suggestion. I have included the check of this header in 1bef54c.

I cannot accept your PR for several reasons: it is not complete (this tool allows to show results in English and Spanish and therefore it is necessary to modify the corresponding files to show the messages in both languages). Additionally your PR removes an insecure value check from this header, which I think is necessary.

I have included your suggestion at https://github.com/rfc-st/humble/#acknowledgements. Thanks again for your time!.

Best regards,

@rfc-st rfc-st closed this as completed Oct 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants