3 ms·
Though we don't hit every one of your points, the Lift framework (http://liftweb.net/ http://liftweb.net/) hits a lot of them, and aims to be secure by default
by shadowfiend 13y ago
Though we don't hit every one of your points, the Lift framework (http://liftweb.net/ http://liftweb.net/) hits a lot of them, and aims to be secure by default as much as possible. XSS is difficult by default because everything lives in a reified XML tree more or less until it goes down the pipe. SiteMap, which is the way that you do routing, disables access to anything that isn't explicitly declared in the site map. CSRF is based on randomized ids for each field and form, tied to this session, this page, and a specific callback function on the server. Content-Security-Policy isn't configured by default at the moment, though that's a good idea to add. X-Frame-Options is set by default. A bit more at http://seventhings.liftweb.net/security http://seventhings.liftweb.net/security .
- elwell 13y agoIt took me about 5 minutes to realize Lift is for Scala. It doesn't say that anywhere on the website that I could tell.
- shadowfiend 13y agoYeah… The site needs work. So does some of the intro documentation (there are a few good books on it, but I mean on-site intro documentation). We're working on these things, and hope to have something awesome to show in the next few months.