The following warnings occurred:
Warning [2] Undefined variable $unreadreports - Line: 26 - File: global.php(961) : eval()'d code PHP 8.2.25 (Linux)
File Line Function
/global.php(961) : eval()'d code 26 errorHandler->error
/global.php 961 eval
/showthread.php 28 require_once





× This forum is read only. As of July 23, 2019, the UserSpice forums have been closed. To receive support, please join our Discord by clicking here. Thank you!

  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
zxcvbn bootstrap password strength meter and secure headers mods
#10
I am not an expert on site security - it would appear that as soon as one security hole is plugged another will appear. Hackers can be extremely resourceful and the best one can do is make life as difficult as possible for the hacker without making your application unusable.

As with password choices, security headers could be offered as an option for users to make. A basic set of secure headers could be recommended for all users with others as an option. Much would depend upon what type of application each user is developing.

http://searchsecurity.techtarget.com/ans...a-security offers some advice on cache control.

Perhaps a suck and see approach is the best option when you do not know how Userspice is going to be used by a user. Offer a list of headers for selection/deselection on the understanding that if selected and everything still works then one more potential security hole has been blocked.
  Reply


Messages In This Thread
zxcvbn bootstrap password strength meter and secure headers mods - by Jeff - 11-28-2017, 02:45 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)