Repository navigation
Warn legacy browsers that do not support Content Security Policy - #29957
Conversation
|
Pinging @elastic/kibana-security |
The new csp.warnLegacyBrowsers configuration is enabled by default, and it shows a warning message to any legacy browser when they access Kibana to indicate that they are not enforcing the basic security protections of the current install. The protections check is the same as csp.strict, so this feature is designed to be used as an alternative to aid in BWC. When csp.strict is enabled, warnLegacyBrowsers is effectively ignored.
6da8c5d to
301f6d1
Compare
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
I think we need to be a little more specific with the browser version and what application refers to. Here's a suggestion: Your browser version does not enforce the basic security protections of this installation of Kibana. Or, a little bit more readable: Your browser version does not meet the basic security requirements of this installation of Kibana. |
|
From a functionality perspective, this is looking good and it works properly in IE11. |
This comment has been minimized.
This comment has been minimized.
|
@gchaps Those options push the text onto an additional line which makes it hard to read before the toast disappears. I ended up going with your second suggestion minus the word I suspect we'll be overhauling the whole warning into a more appropriate format in a future version so we can add more clarifying text. |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
Either of these versions might be 2 lines: Your browser doesn't meet the security requirements for Kibana. |
|
I pushed tests for these changes along with an update to the toast message based on the latest suggestions from @gchaps: Assuming CI goes green, this should be good to go. |
This comment has been minimized.
This comment has been minimized.
|
Looks like some test code snuck in there: 6f60732#diff-9bd94cfd030783be3e58200ce3f9b3a9R75 |
This comment has been minimized.
This comment has been minimized.
|
@epixa That looks good. If you'd add a period at the end of the sentence, I'd be very happy. |
|
I added a period to the toast message and removed that dev code I accidentally committed. Don't commit in a rush, folks! |
💚 Build Succeeded |
💔 Build Failed |
…stic#29957) * csp: warn legacy browsers that do not support CSP The new csp.warnLegacyBrowsers configuration is enabled by default, and it shows a warning message to any legacy browser when they access Kibana to indicate that they are not enforcing the basic security protections of the current install. The protections check is the same as csp.strict, so this feature is designed to be used as an alternative to aid in BWC. When csp.strict is enabled, warnLegacyBrowsers is effectively ignored. * fix ChromeService tests * more test fixes * csp injectvars in legacy test bundle * update warning text and make it translatable * no need to warn in legacy browser unit tests * tests for chrome legacy browser warning * document legacy browser warning breaking change * update csp warning toast message * add period, remove dev code
The new csp.warnLegacyBrowsers configuration is enabled by default, and
it shows a warning message to any legacy browser when they access Kibana
to indicate that they are not enforcing the basic security protections
of the current install.
The protections check is the same as csp.strict, so this feature is
designed to be used as an alternative to aid in BWC. When csp.strict is
enabled, warnLegacyBrowsers is effectively ignored.
Follow up to #29856