Skip to content

Commit 4bd5127

Browse files
authored
Validators: allow https: as allow-all * value in CSP frame-ancestors check (#677)
* fix: treat CSP frame-ancestors scheme-source (https:) as permissive * change comment
1 parent a7ecaa2 commit 4bd5127

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎lib/plugins/validators/async/21_checkContentType.js‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,6 +95,7 @@ export default {
9595

9696
if (frame_ancestors) { // allow only if it contains " * " or "http://*" or "https://*"
9797
frame_ancestors = frame_ancestors.replace(/https?:\/\/\*/ig, '*'); // Ex. Behance video streams via Adobe CDN
98+
frame_ancestors = frame_ancestors.replace(/\bhttps?:(?!\S)/ig, '*'); // Ex. "frame-ancestors https:" - scheme-only means any HTTPS origin
9899
frame_ancestors = frame_ancestors.replace(/^\*/i, ' *');
99100
frame_ancestors = frame_ancestors.replace(/\*$/i, '* ');
100101
if (frame_ancestors.indexOf(' * ') == -1) {

0 commit comments

Comments
 (0)