View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0021908 | mantisbt | security | public | 2016年11月13日 06:45 | 2026年05月14日 07:40 |
| Reporter | atrol | Assigned To | |||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | confirmed | Resolution | open | ||
| Target Version | 2.29.0 | ||||
| Summary | 0021908: Weakened security headers in 2.0.x | ||||
| Description | 2.0.x comes with http_csp_add( 'style-src', "'unsafe-inline'" ); in http_api.php. | ||||
| Tags | csp | ||||
Why you don't allow unsafe-inline styles in 1.3.x. ?
Why you don't allow unsafe-inline styles in 1.3.x. ?
Wrong question, it should be: Why you allow unsafe-inline styles in 2.x?
Allowing unsafe-inline styles decreases security.
That's why I reported the issue.
@yanual I suggested you read https://stackoverflow.com/a/31759553/1045774 for a brief explanation of the potential risks to your site when unsafe-inline styles are allowed.
@atrol your formulation is indeed better.
Ok, I will wait patiently for postponement of the treatment of the issue.
@degrad i know these risks.
For no particular reason (0019307), I started looking into CSP in MantisBT and also came to the conclusion that the call http_csp_add( ‘style-src’, "‘unsafe-inline’" ); should be removed from http_api.php. To do this correctly, all uses of the style attribute must first be removed from all HTML within MantisBT. But even without considering CSP, switching from inline style attributes to external class selectors is a more versatile approach to web design, offering improved maintainability and code structure, and better performance.
PR (draft): https://github.com/mantisbt/mantisbt/pull/2219
Copyright © 2000 - 2026 MantisBT Team
Contact administrator for assistance