secutils icon indicating copy to clipboard operation
secutils copied to clipboard

Enable users to monitor their created content security policies for the most common issues

Open azasypkin opened this issue 2 years ago • 0 comments

Summary

Currently, we only allow users to create, store, and deploy content security policies. We don't provide any capabilities to help them ensure that the policies are correctly deployed and remain correct throughout their entire lifespan.

There are several common issues with CSP that we can potentially check for: non-unique nonces, deprecated directives, unexpected changes in the deployed policy, or unintentionally removed policies. Here's how we can display this information in the Secutils.dev UI:

Prerequisites

  • [ ] We need a way for users to specify their email we'll use to report detected issues. Later we can add Slack/messengers integrations.
  • [ ] We need a "cron job"-like module to perform periodic checks

azasypkin avatar Jun 07 '23 06:06 azasypkin