【问题标题】:X-Content-Security-Policy-Report-Only not working in Firefox 20X-Content-Security-Policy-Report-Only 在 Firefox 20 中不起作用
【发布时间】:2013-05-03 21:53:27
【问题描述】:

我定义了以下内容安全策略:

X-Content-Security-Policy-Report-Only: default-src 'self'; report-uri /foo

如果我将其更改为 X-Content-Security-Policy,则会强制执行该策略并发送报告。但是,当我将其设置为 Report-Only 时,控制台中不会出现任何策略警告,也不会发送任何报告。

我知道他们不支持 unsafe-inline 和 unsafe-eval 的错误,而您必须使用 options inline-script eval-script,但我在此页面上没有使用任何一个。

我不知道这是否与它有很大关系,但标头被发送为 X-Content-Security-Policy-Report-Only,但 Firebug 将其转换为 x-content-security-policy-report-only - 只是改变大小写。

此外,当同时提供 X-Content-Security-Policy 和 X-Content-Security-Policy-Report-Only 时,如下所示:

X-Content-Security-Policy: default-src 'self'; options inline-script; report-uri /csp-report.php
x-content-security-policy-report-only: default-src 'self'; report-uri /csp-report.php

控制台有一条WARN级别消息:

仅报告 CSP 政策将被忽略,因为还有其他 应用了非仅限报告的 CSP 政策。

所以它看到了标题,而不是处理它并报告但强制执行另一个,它完全放弃了它?

【问题讨论】:

    标签: firefox content-security-policy


    【解决方案1】:

    呃——我以前看过错误报告,但没有仔细阅读,还以为是unsafe-inline 或unsafe-eval 的问题。 https://bugzilla.mozilla.org/show_bug.cgi?id=687086 实际上专门讨论了内联脚本不会触发策略,因为允许脚本运行。对违反政策的其他事物进行测试(例如从其他地方加载脚本),生成并发送报告。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2018-09-05
      • 1970-01-01
      • 2022-01-21
      • 2021-12-18
      • 2015-09-09
      • 2023-03-19
      • 2018-05-04
      相关资源
      最近更新 更多