Back to bug 2160664

Who When What Removed Added
Red Hat Bugzilla 2023-01-13 08:54:24 UTC Pool ID sst_high_availability_rhel_9
Tomas Jelinek 2023-01-13 08:55:44 UTC Link ID Red Hat Bugzilla 2097778
Tomas Jelinek 2023-01-13 08:56:14 UTC Doc Type If docs needed, set a value Enhancement
Red Hat One Jira (issues.redhat.com) 2023-01-13 08:56:50 UTC Link ID Red Hat Issue Tracker RHELPLAN-145013
Tomas Jelinek 2023-02-01 12:39:47 UTC Target Release --- 9.3
Priority unspecified low
Michal Mazourek 2023-02-07 10:51:55 UTC CC mmazoure
Tomas Jelinek 2023-02-20 12:15:04 UTC Status NEW ASSIGNED
Tomas Jelinek 2023-02-22 15:23:57 UTC Doc Text Feature:
Instruct web browsers to only load resources directly from pcs web UI and no other sources even when an error page is sent to a browser.

Reason:
This helps guard against cross-site scripting attacks.

Result:
HTTP header "Content-Security-Policy: frame-ancestors 'self'; default-src 'self'" is sent by pcsd in error HTTP responses instructing web browsers to only load and run resources from pcs web UI and no external sources.
Status ASSIGNED POST
Dean Jansa 2023-04-19 22:23:48 UTC Link ID Red Hat Issue Tracker CLUSTERQE-6628
Steven J. Levine 2023-05-05 18:02:32 UTC CC slevine
Flags needinfo?(tojeline)
Tomas Jelinek 2023-05-15 10:27:23 UTC Flags needinfo?(tojeline)
Michal Pospisil 2023-05-26 09:27:52 UTC Fixed In Version pcs-0.11.5-1.el9
Status POST MODIFIED
Nina Hostakova 2023-06-01 12:09:31 UTC CC nhostako
errata-xmlrpc 2023-06-02 05:16:43 UTC Status MODIFIED ON_QA
Michal Mazourek 2023-07-17 15:28:50 UTC Status ON_QA VERIFIED
Red Hat Bugzilla 2023-08-10 15:40:15 UTC QA Contact cluster-qe cluster-qe
CC cluster-qe

Back to bug 2160664