Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate setting Permissions-Policy HTTP headers #2298

Closed
tas50 opened this issue Oct 14, 2021 · 1 comment
Closed

Investigate setting Permissions-Policy HTTP headers #2298

tas50 opened this issue Oct 14, 2021 · 1 comment
Assignees
Labels
Aspect: Security Can an unwanted third party affect the stability or look at privileged information?

Comments

@tas50
Copy link
Contributor

tas50 commented Oct 14, 2021

Investigate setting Permissions-Policy in Supermarket. This is possible in Rails 6.1, but it may need to be done in Nginx. We should probably disable camera and payment to start since those are 100% not used by Supermarket.

https://blog.saeloun.com/2019/10/01/rails-6-1-adds-http-feature-policy.html

@tas50 tas50 added Status: Untriaged An issue that has yet to be triaged. Aspect: Security Can an unwanted third party affect the stability or look at privileged information? and removed Status: Untriaged An issue that has yet to be triaged. labels Oct 14, 2021
@RajeshPaul38 RajeshPaul38 self-assigned this Nov 18, 2021
@RajeshPaul38
Copy link
Contributor

similar requirement in this PR: https://github.com/chef/chef-manage/pull/1227

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Aspect: Security Can an unwanted third party affect the stability or look at privileged information?
Projects
None yet
Development

No branches or pull requests

2 participants