Skip to content

Model the CSP sandbox #83

@lsd-cat

Description

@lsd-cat

The current CSP sandbox is based on my understanding of the CSP spec, but we know I missed some that could have allowed for bypasses, etiher because of inheritances or different type of sources. Would be nice if we modeled the CSP spec in something like z3, then my validating function, and then we solved to look for javascript/css/objects execution vectors.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions