[E30-S04] CSP frame-src generation from the provider table #119

Open
opened 2026-08-27 00:03:27 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E30] Embeds (#56)

Intent

Generate the CSP frame-src directive from the provider table so the browser enforces the same allowlist as the renderer.

Acceptance criteria

  • Generate the CSP frame-src directive from the eppp_embed_providers table
  • Enforce the allowlist twice: in the renderer and via the browser CSP frame-src
  • Block an iframe from a non-allowlisted host in the browser as well as in the renderer

Explicitly out of scope

  • Provider allowlist administration is covered by E30-S02
  • Embed resolution and snapshot caching is covered by E30-S03

Test plan

  • Assert frame-src contains exactly the allowlisted hostnames
  • Load an iframe from a non-allowlisted host and assert the browser blocks it

Rollback note

  • Revert the CSP header generation; no data change

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E30] Embeds (#56) ## Intent Generate the CSP `frame-src` directive from the provider table so the browser enforces the same allowlist as the renderer. ## Acceptance criteria - Generate the CSP `frame-src` directive from the `eppp_embed_providers` table - Enforce the allowlist twice: in the renderer and via the browser CSP `frame-src` - Block an iframe from a non-allowlisted host in the browser as well as in the renderer ## Explicitly out of scope - Provider allowlist administration is covered by E30-S02 - Embed resolution and snapshot caching is covered by E30-S03 ## Test plan - Assert `frame-src` contains exactly the allowlisted hostnames - Load an iframe from a non-allowlisted host and assert the browser blocks it ## Rollback note - Revert the CSP header generation; no data change ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint M milestone 2026-08-27 00:03:27 +00:00
kpcto added the
status
proposed
kind
story
labels 2026-08-27 00:03:27 +00:00
Sign in to join this conversation.