Re: Contribution - CSP support for Wicket

2020-06-05 Thread Santiago Díaz
Thanks Edmond! This seems like the right opportunity to pick this ticket up. I've added it to our references :) stay tuned! On 2020/06/05 12:56:00, Emond Papegaaij wrote: > Hi Santiago, > > It's always nice to get some help in maintaining Wicket. Wicket has > always been strong wrt security.

Re: Contribution - CSP support for Wicket

2020-06-05 Thread Emond Papegaaij
Hi Santiago, It's always nice to get some help in maintaining Wicket. Wicket has always been strong wrt security. That's one of the reasons why at Topicus we use it to power our Identity and Access Management solution called Topicus KeyHub. Just a few weeks ago I filed the following ticket

Re: Contribution - CSP support for Wicket

2020-06-05 Thread Santiago Díaz
Hello Wicket devs! Thanks for pointing out the Jira tickets that I missed! I didn't realise that you already have extensive CSP support. Great job on getting rid of both unsafe-inline & unsafe-eval! In that case, we will be shifting focus towards improving Wicket's security through one or

Re: Contribution - CSP support for Wicket

2020-06-05 Thread Andrew Kondratev
Hi Santiago, Feel free to follow Wicket dev community discussion on this subject at https://lists.apache.org/thread.html/rbd8b1500fff1140d136a08e35cf8c0f5cf200bf8a60b6a58204ef9a7%40%3Cdev.wicket.apache.org%3E чт, 4 июн. 2020 г. в 21:47, Santiago Díaz : > Hello Andrew, > > My name is Santiago,

Re: Contribution - CSP support for Wicket

2020-06-05 Thread Andrew Kondratev
>> IMO we should explain that the CSP support has been already added in 9.x >> and to close this forgotten JIRA ticket. >> Then if they still think there are ways to improve the current >> implementation they are very welcome to contribute! Martin, I did tell it first: >> Hi Santiago. >> >> The

Re: Contribution - CSP support for Wicket

2020-06-05 Thread Martin Grigorov
Hi, On Fri, Jun 5, 2020 at 6:17 AM Tobias Soloschenko wrote: > Hi, > > to my opinion they just want to contribute to Wicket. I would simply > explain how the process of contribution works at ASF (PRs, etc.) and give > them some information what challenges we were faced with till now. > IMO we