[ 
https://issues.apache.org/jira/browse/WICKET-7093?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17824675#comment-17824675
 ] 

ASF subversion and git services commented on WICKET-7093:
---------------------------------------------------------

Commit 6f9e5e2695f23bedb5b73754506ac8c6eb165186 in wicket's branch 
refs/heads/master from Mateusz Kaczmarczyk
[ https://gitbox.apache.org/repos/asf?p=wicket.git;h=6f9e5e2695 ]

WICKET-7093: Adding "form-action" to the CSP Directives (#801)

* WICKET-7093: Adding form-action to the CSP Directives

* WICKET-7093: Fix a typo in the enum name

---------

Co-authored-by: Martin Grigorov <marti...@users.noreply.github.com>
(cherry picked from commit 0ff2492122638aebb7ce3a7f67c444cd7f64f9a1)


> Add support for missing CSP directives
> --------------------------------------
>
>                 Key: WICKET-7093
>                 URL: https://issues.apache.org/jira/browse/WICKET-7093
>             Project: Wicket
>          Issue Type: Improvement
>          Components: wicket
>    Affects Versions: 9.16.0
>            Reporter: Martin Tzvetanov Grigorov
>            Priority: Minor
>
> A user at StackOverflow reported that the CSP directive `form-action` is not 
> supported: 
> https://stackoverflow.com/questions/77768942/missing-form-action-csp-directive-in-cspdirective
> Looking at 
> https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/form-action
>  and 
> https://github.com/apache/wicket/blob/c4a77c4ee7b7ec1dd5d071ed6e1e41a9946d6758/wicket-core/src/main/java/org/apache/wicket/csp/CSPDirective.java#L36-L48
>  I think there are few more that are listed in the CSPDirective enum.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to