Back to bug 2160555

Who When What Removed Added
Red Hat Bugzilla 2023-01-12 20:22:41 UTC Pool ID sst_high_availability_rhel_8
Red Hat One Jira (issues.redhat.com) 2023-01-12 20:24:53 UTC Link ID Red Hat Issue Tracker RHELPLAN-144988
Tomas Jelinek 2023-01-13 08:51:17 UTC Doc Type If docs needed, set a value Enhancement
Link ID Red Hat Bugzilla 2097778
Keywords Triaged
Tomas Jelinek 2023-01-13 08:54:24 UTC Depends On 2160664
Tomas Jelinek 2023-02-01 12:39:20 UTC Target Release --- 8.9
Tomas Jelinek 2023-02-01 12:40:04 UTC Priority unspecified low
Michal Mazourek 2023-02-07 10:50:33 UTC CC mmazoure
Tomas Jelinek 2023-02-20 12:15:01 UTC Status NEW ASSIGNED
Tomas Jelinek 2023-02-22 15:20:20 UTC Doc Text Feature:
Instruct web browsers to only load resources directly from pcs web UI and no other sources even when an error page is sent to a browser.

Reason:
This helps guard against cross-site scripting attacks.

Result:
HTTP header "Content-Security-Policy: frame-ancestors 'self'; default-src 'self'" is sent by pcsd in error HTTP responses instructing web browsers to only load and run resources from pcs web UI and no external sources.
Status ASSIGNED POST
Dean Jansa 2023-04-19 21:53:03 UTC Link ID Red Hat Issue Tracker CLUSTERQE-6611
Michal Pospisil 2023-05-29 10:09:46 UTC Fixed In Version pcs-0.10.16-1.el8
Status POST MODIFIED
errata-xmlrpc 2023-05-30 20:16:54 UTC Status MODIFIED ON_QA
Michal Mazourek 2023-07-17 15:35:08 UTC Status ON_QA VERIFIED
Red Hat Bugzilla 2023-08-10 15:40:25 UTC QA Contact cluster-qe cluster-qe

Back to bug 2160555