From 10ecbddeae33d2659ae0e281b33414d1b745e0f6 Mon Sep 17 00:00:00 2001 From: acaptutorials Date: Mon, 17 Feb 2025 02:41:03 +0800 Subject: [PATCH] docs: additional note on xss details --- docs/pages/announcements/firebase-storage-2024.mdx | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/docs/pages/announcements/firebase-storage-2024.mdx b/docs/pages/announcements/firebase-storage-2024.mdx index f54b3497..3c176d14 100644 --- a/docs/pages/announcements/firebase-storage-2024.mdx +++ b/docs/pages/announcements/firebase-storage-2024.mdx @@ -148,10 +148,14 @@ Yes. Some of the latest core deliverables implemented for ACAP in its [2. This table shows the overall security criteria ensured and accounted for by ACAP's best practices in its recommended [security guidelines](/security). + +The reduced enforcement of **Cross-Site Scripting (XSS) protection** particularly affects the WYSIWYG-form Crop Recommendations, leading to a reproducible security vulnerability. A [detailed description](https://github.com/amia-cis/acap-v2/issues/34) is available in the parent **acap-v2** GitHub issues list, with a video demonstration available upon request. + + | Criteria | Purpose | ACAP [1.0](/changelog/#version-1-acap-10) | ACAP [2.0](/changelog/#version-2-acap-20) | | --- | --- | :---: | :---: | | User authentication | Authorized, allowed, and predictable operations access to resources | ✅ | ✅ | -| Cross-Site Scripting (XSS) Protection | Predictable billing, reliable/authentic website information, user information confidentiality, predictable data manipulation / SMS sending, protection for unvalidated writes that allow tampering with stored data, impacting system reliability, protection for injecting malicious scripts that steal user info or redirect users to phishing sites (and protection for other uncontrolled scenarios that stem from XSS) | ✅ | ❌ | +| **Cross-Site Scripting (XSS) Protection** | Predictable billing, reliable/authentic website information, user information confidentiality, predictable data manipulation / SMS sending, protection for unvalidated writes that allow tampering with stored data, impacting system reliability, protection for injecting malicious scripts that steal user info or redirect users to phishing sites (and protection for other uncontrolled scenarios that stem from XSS) | ✅ | ❌ | | Cloud storage protection | Authorized, allowed, and predictable operations access to storage, predictable billing | ✅ | ✅ | | Database integrity | Accuracy, consistency, and reliability of data stored in a database and presented to users | ✅ | ❌ | | Database protection | Authorized, allowed, and predictable operations access to the (Firestore) database, predictable billing | ✅ | ❌ |