Skip to content

Commit

Permalink
#1274 - no sensitive data to trackers
Browse files Browse the repository at this point in the history
  • Loading branch information
elarlang authored and tghosth committed Jan 25, 2024
1 parent a3e1819 commit b4922e6
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions 5.0/en/0x16-V8-Data-Protection.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ Ensure that a verified application satisfies the following high level data prote
| **8.1.5** | [DELETED, NOT IN SCOPE] | | | | |
| **8.1.6** | [DELETED, NOT IN SCOPE] | | | | |
| **8.1.7** | [ADDED] Verify that caching mechanisms are configured to only cache responses which have the correct content type and do not contain sensitive, dynamic content. The web server should return a 404 or 302 response when an non-existent file is accessed rather than returning a different, valid file. This should prevent Web Cache Deception attacks. | ||| 444 |
| **8.1.8** | [ADDED] Verify that defined sensitive data is not sent to untrusted parties (e.g. user trackers) to prevent unwanted collection of data outside of the application's control. | ||| 200 |

## V8.2 Client-side Data Protection

Expand Down

0 comments on commit b4922e6

Please sign in to comment.