The following warnings occurred:
Warning [2] Undefined variable $unreadreports - Line: 26 - File: global.php(961) : eval()'d code PHP 8.2.25 (Linux)
File Line Function
/global.php(961) : eval()'d code 26 errorHandler->error
/global.php 961 eval
/showthread.php 28 require_once





× This forum is read only. As of July 23, 2019, the UserSpice forums have been closed. To receive support, please join our Discord by clicking here. Thank you!

  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
zxcvbn bootstrap password strength meter and secure headers mods
#4
Secure Headers modification for 4.3.4

Copy and paste the code in the HTML pane from https://codepen.io/Scally/pen/wPyjgd

modified version of header.php
location: users/includes folder

Seven security headers are identified in this modification, only the content-security-policy HTTP header has not been applied.
My understanding is that the content-security-policy header provides a whitelist of approved external and internal sources of files used by the site.
It would be possible to identify those sources used by UserSpice, but you are not able to identify sources needed in user pages.

With each header I have given optional settings that might be used to tweak performance.

I hope the settings I have started with and the location of the mod in the header.php file are OK.
I have used https://securityheaders.io/ to scan the site before and after applying this modification.
  Reply


Messages In This Thread
zxcvbn bootstrap password strength meter and secure headers mods - by Jeff - 11-20-2017, 07:01 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)