home.social

#csp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #csp, aggregated by home.social.

fetched live
  1. Offenbar injected uBlock Origin neuerdings über eine globale Filterregel das Scriptlet prevent-clipboard-write in ALLE Webseiten.

    Schöne Idee, wenn man strikte CSPs mit Reporting verwendet wie ich. 🤦🏼‍♂️

    Grotesk wird es dann, wenn man die Option "Block CSP reports" in uBlock Origin aktiviert hat. Dann blockt er den selbst verursachten CSP Report weg. 🤦🏼‍♂️

    Kann man alles machen., weiß allerdings nicht, ob ich das gut finde.

    #uBlockOrgin #CSP #Scriptlet #Injection

  2. Картинка грузится, а fetch к тому же хосту — нет: как CSP тихо сломала три интеграции

    Полгода назад я закрыл замечание аудита «на сайте нет CSP» — прописал Content‑Security‑Policy с белым списком хостов, проверил, что ничего не отвалилось, и забыл. За три дня на прошлой неделе я нашёл три интеграции, которые эта политика убила молча. Ни одна из них не оставила следа на сервере. Страница, которая называет себя «в реальном времени», показывала одно и то же число десять секунд подряд — и показывала так всем, с того самого дня, как я включил CSP. Это заметка про то, почему такие поломки не видно, и про скрипт, который находит их все сразу.

    habr.com/ru/articles/1066450/

    #csp #contentsecuritypolicy #connectsrc #nextjs #отладка #мониторинг #фронтенд

  3. Bon du coup, pourquoi le profil #CSP+ des #usagers #autopartage ? (voir 🧵 3 et 31 ⬆️ )

    Eh bien pas vraiment de réponse dans le document, à part l'attachement culturel à la voiture et le statut social associé.

    Mais comme on le voit avec la perception du #vélo, c'est un gros morceau.

    🧵 32

  4. Qui sont les #autopartageurs ?

    Bon, encore très #CSP+ #homme #actif ... et ça n'a pas changé depuis 2019.

    Le côté "urbain" est un peu forcé en tout cas pour démarrer un service, car c'est dans les zones denses que cela peut marcher avec une faible proportion d'usagers.

    Je veux voir à la lecture si le côté CSP+ est culturel ou lié à des contraintes différentes...

    Et pourquoi masculin ?? (Ou bien c'est du fait des adhésions par foyer, avec un report plus sur le mec parce que voiture ?)

    🧵3

  5. PSA for future me (and apparently the other three people on Earth who will ever need this):

    If you need the SHA-256 digest of the number "0" because your CSP is so aggressively locked down that you have to whitelist "<script>0</script>" just to stop Gecko from flashbanging users with unstyled content...

    echo -n "0" | openssl dgst -sha256 -binary | base64
    X+zrZv/IbzjZUnhsbWlsecLbwjndTpG0ZynXOif7V+k=

    #Programming is a normal profession.

    #gecko #CSP #InfoSec #WebDev #Firefox #SysAdmin

  6. Secure your iframes with CSP's frame-src and sandbox. This config restricts which origins load in iframes and applies extra constraints like blocking scripts or forms. Works on Nginx/Apache, Ubuntu/Debian. #web #csp #ValtersIT

    valtersit.com/vault/csp-with-f

  7. Hardening video streaming? This CSP blocks mixed content, locks script-src to 'self' + trusted analytics, and whitelists CDNs for media-src and img-src. Works on Ubuntu/Debian with Nginx/Apache. #web #csp #ValtersIT

    valtersit.com/vault/csp-with-m

  8. 𝗟𝗮𝗯𝗼𝗿𝗮𝘁𝗼𝗿𝘆:

    #Browser #Firefox #Security #CSP

    thewhale.cc/posts/laboratory

    Laboratory is an experimental Firefox extension that helps you generate a Content Security Policy (CSP) header for your website.