Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP report-hash keyword #1020

Open
1 task done
yoavweiss opened this issue Nov 26, 2024 · 0 comments
Open
1 task done

CSP report-hash keyword #1020

yoavweiss opened this issue Nov 26, 2024 · 0 comments

Comments

@yoavweiss
Copy link

yoavweiss commented Nov 26, 2024

こんにちは TAG-さん!

I'm requesting a TAG review of CSP hash reporting.

Complex web applications often need to keep tabs of the subresources that they download, for security purposes.

In particular, upcoming industry standards and best practices (e.g. PCI-DSS v4 - context) require that web applications keep an inventory of all the scripts they download and execute.

This feature is a new CSP keyword, that would enable web developers to create and maintain such inventories in a secure manner.

Further details:

  • I have reviewed the TAG's Web Platform Design Principles
  • Relevant time constraints or deadlines: As the relevant security standards go into effect in March 2025, I'd like to ship this in the next month or so.
  • The group where the work on this specification is currently being done: WebAppSec
  • The group where standardization of this work is intended to be done (if different from the current group):
  • Major unresolved issues with or opposition to this specification:
  • This work is being funded by: Shopify

You should also know that this work is critical for PCI-DSS v4 - context.

@yoavweiss yoavweiss changed the title CSP report-hash directive CSP report-hash keyword Dec 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant