Page MenuHomeMiraheze

Create a CSP whitelist policy
Closed, DeclinedPublic

Description

We've received quite a few CSP whitelist requests, and obviously the CSP is there to prevent abuse so whitelisting any requested URL would defeat its purpose so that's why we need a policy for how we decide what to whitelist or not.

Event Timeline

Reception123 triaged this task as Normal priority.Jan 11 2020, 09:01
Reception123 created this task.
Reception123 claimed this task.

We're going to go for an informal policy which is that each request is case by case and users must be able to explain why the whitelist is essential for the functioning of their wiki. The decision to add it to the CSP should be approved by 2 SRE members.