•  
      request #7877 Content Security Policy header has an invalid value
    Infos
    #7877
    Thomas Gerbet (tgerbet)
    2015-03-04 16:22
    2015-02-18 10:08
    7883
    Details
    Content Security Policy header has an invalid value

    Chromium >38 starts to use the Content Security Policy directive reflected-xss. The current directive value is invalid:

    The 'reflected-xss' Content Security Policy directive has the invalid value "'block'". Valid values are "allow", "filter", and "block".

    Reference

    http://www.w3.org/TR/CSP2/#reflected-xss

    Other
    7.10
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2015-02-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Merged in Tuleap 7.10.99.25

    • Status changed from Under review to Closed
    • Close date set to 2015-02-18
    User avatar
    Thomas Gerbet (tgerbet)2015-02-18 10:12
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes