Details
Alert Id 10063
Alert Type Passive Scan Rule
Status alpha
Risk
CWE
WASC

Summary

Feature Policy Header is an added layer of security that helps to restrict from unauthorized access or usage of browser/client features by web resources. This policy ensures the user privacy by limiting or specifying the features of the browsers can be used by the web resources. Feature Policy provides a set of standard HTTP headers that allow website owners to limit which features of browsers can be used by the page such as camera, microphone, location, full screen etc.

Solution

Ensure that your web server, application server, load balancer, etc. is configured to set the Feature-Policy header.

References

Code

org/zaproxy/zap/extension/pscanrulesAlpha/FeaturePolicyScanRule.java