Search code examples

Unable to find the Wildcard directive in my CSP

I conducted a ZAP assessment on my application, I received a flag 'CSP: Wildcard Directive' which has high confidence level. Still, I have not been able to locate the source of the wildcard directive. The CSP I use now:

script-src 'self' 'nonce-randomNonce'; style-src 'self' 'nonce-randomNonce'; font-src 'self'; img-src 'self' ; worker-src 'self' blob:; connect-src 'self';

Some notes:

  • The nonce in the header has been hardcoded as I am still working on generating random nonces

  • I expect the test to pass without any warnings since I am not using '*' anywhere.

Can someone find what is responsible for Wildcard Directive flag, or what is it that I am missing?



  • There are a set of CSP directives that do not fall back to default source. If you haven't defined them it's the same as setting *

    If you check the "Other Info" of the alert you should see specifics.

    The following directives don't use default-src as a fallback. Remember that failing to set them is the same as allowing anything:

    • base-uri
    • form-action
    • frame-ancestors
    • plugin-types
    • report-uri
    • sandbox