Skip to content

CSP evaluator doesn't support newest the newest CSP directives and keywords and breaks some policies #60

@GalacticHypernova

Description

@GalacticHypernova

Like stated in #54 and #56 there are some additions to CSP that the evaluator does not recognize, which makes it inaccurate in analyzing most up-to-date policies. The directives that aren't supported include but aren't limited to:

  1. wasm-unsafe-eval Hosted CSP Evaluator doesn't recognize 'wasm-unsafe-eval' #54, Mozilla
  2. inline-speculation-rules CSP extension for speculation rules #56
  3. unsafe-hashesCSP.com, Mozilla
    Also, the evaluator gets the some keywords wrong , for example hashes, and autocompletes to sha-512- and sha-384- in stead of sha512- and sha384- which breaks the policy by prodiving inaccurate keywords.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions