[wp-trac] [WordPress Trac] #10237: Implement Content Security Policy to prevent XSS

WordPress Trac noreply at wordpress.org
Thu Dec 3 17:27:33 UTC 2015


#10237: Implement Content Security Policy to prevent XSS
-------------------------------+----------------------
 Reporter:  Denis-de-Bernardy  |       Owner:
     Type:  feature request    |      Status:  closed
 Priority:  normal             |   Milestone:
Component:  Security           |     Version:  2.8
 Severity:  normal             |  Resolution:  wontfix
 Keywords:                     |     Focuses:
-------------------------------+----------------------
Changes (by johnbillion):

 * keywords:  needs-patch =>
 * status:  assigned => closed
 * resolution:   => wontfix
 * milestone:  Future Release =>


Comment:

 I think this is firmly plugin territory. An admin screen for managing CSP
 is not something that's user friendly to users who don't have a firm
 understanding of CSP and its consequences.

 Adding a default CSP rule to the admin area in WordPress is a separate
 issue and should be in a separate ticket.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/10237#comment:27>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list