Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide console command to review security settings #35

Open
ghost opened this issue Oct 24, 2014 · 2 comments
Open

Provide console command to review security settings #35

ghost opened this issue Oct 24, 2014 · 2 comments

Comments

@ghost
Copy link

ghost commented Oct 24, 2014

The console command should inspect the current security settings and give hints which settings should also be enabled.

  • report missing CSP directives (neither enforced nor reported)
  • report other missing security features like Clickjacking Protection, Forced HTTPS/SSL Handling

Such a reporting might be especially useful if new CSP versions add new directives or if entirely new security mechanisms are added to this bundle.

@Seldaek
Copy link
Member

Seldaek commented Nov 11, 2014

Not against it but I am unlikely to find time to work on it so if you or anyone else would like to send a pull request that'd be great.

@bartveneman
Copy link

A bit like https://report-uri.io/home/analyse/ does? (Try entering https://github.com/ as url)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants