spring-security icon indicating copy to clipboard operation
spring-security copied to clipboard

Add lambda DSL method for featurePolicy

Open jzheaux opened this issue 7 months ago • 2 comments

Even though Permission-Policy is targeted to replace Feature-Policy, browsers still largely support Feature-Policy, not Permission-Policy. Further , Permission-Policy is still in draft.

As such, we should add the lambda DSL for featurePolicy to HeadersConfigurer and to ServerHttpSecurity. We should also consider removing deprecation markers for Feature-Policy from the Servlet, Reactive, and Kotlin DSLs.

Related #9262

jzheaux avatar Jun 20 '25 17:06 jzheaux

Hi, @jzheaux! You marked this as ideal-for-contribution, so I guess I can try to solve this issue?

therepanic avatar Jun 20 '25 17:06 therepanic

For sure, @therepanic, thanks for volunteering!

jzheaux avatar Jun 24 '25 13:06 jzheaux

@jzheaux Totally agree — especially given the case you presented and the fact that Permission-Policy is still an experimental technology, the deprecation of Feature-Policy feels premature.

@therepanic Have you had a chance to start on this? If not, I’d be happy to work on adding a DSL for Feature-Policy.

DeepDhamala avatar Jul 05 '25 07:07 DeepDhamala

Hi, @DeepDhamala. I already working on this, thanks

therepanic avatar Jul 05 '25 10:07 therepanic