-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Description
As a follow up to this PR #2757, we should add additional tests that attempts to violate CSPs as a way to confirm that they work as expected.
E.g. for Grafana try to inject content, like an image, into a dashboard from an external source that the CSPs should block.
Additional context
Harbor CSPs have not been added yet as it is waitng on upstream changes to be merged and is thus out of scope for this issue.
This issue should mainly concern itself with OpenSearch and Grafana.
Definition of done
- There exists tests for Grafana that ensures that CSPs block content from forbidden external sources
- There exists tests for OpenSearch that ensures that CSPs block content from forbidden external sources
Metadata
Metadata
Assignees
Labels
No labels