diff --git a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/ecoindex.json b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/ecoindex.json index 811f04d4bb..12fa56f683 100644 --- a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/ecoindex.json +++ b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/ecoindex.json @@ -3,7 +3,7 @@ "width": 1920, "height": 1080, "url": "https://agentsenintervention.anct.gouv.fr/", - "size": 2247.202, + "size": 2247.002, "nodes": 264, "requests": 68, "grade": "C", @@ -11,7 +11,7 @@ "ges": 1.74, "water": 2.61, "ecoindex_version": "5.4.2", - "date": "2023-12-10 02:18:13.538214", + "date": "2023-12-17 02:29:01.838909", "page_type": null } ] \ No newline at end of file diff --git a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/http.json b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/http.json index 7eab25724c..b12195f3f6 100644 --- a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/http.json +++ b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/http.json @@ -1 +1 @@ -{"url":"https://agentsenintervention.anct.gouv.fr/","algorithm_version":2,"end_time":"Sun, 10 Dec 2023 02:30:55 GMT","grade":"C","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"cache-control":"s-maxage=31536000, stale-while-revalidate","content-encoding":"gzip","content-security-policy":"default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data: https://agents-intervention-prod-uploads.s3.fr-par.scw.cloud/ https://agents-intervention-dev-uploads.s3.fr-par.scw.cloud/ https://aie-prod.s3.fr-par.scw.cloud/ https://aie-dev.s3.fr-par.scw.cloud/ https://dev-aei.cellar-c2.services.clever-cloud.com/ https://*.jawg.io/;object-src 'none';script-src 'self' 'unsafe-inline';script-src-attr 'none';connect-src 'self' https://api-adresse.data.gouv.fr/ https://agentsenintervention.anct.gouv.fr/api;style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests","content-type":"text/html; charset=utf-8","cross-origin-opener-policy":"same-origin","cross-origin-resource-policy":"same-origin","date":"Sun, 10 Dec 2023 02:30:54 GMT","etag":"\"4pmw05uh681hgl\"","origin-agent-cluster":"?1","referrer-policy":"no-referrer","server":"envoy","strict-transport-security":"max-age=15552000; includeSubDomains","transfer-encoding":"chunked","vary":"RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Url, Accept-Encoding","x-content-type-options":"nosniff","x-dns-prefetch-control":"off","x-download-options":"noopen","x-envoy-upstream-service-time":"23","x-frame-options":"SAMEORIGIN","x-nextjs-cache":"HIT","x-permitted-cross-domain-policies":"none","x-xss-protection":"0"},"scan_id":45354415,"score":50,"start_time":"Sun, 10 Dec 2023 02:30:52 GMT","state":"FINISHED","status_code":200,"tests_failed":3,"tests_passed":9,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"base-uri":["'self'"],"connect-src":["https://agentsenintervention.anct.gouv.fr/api","'self'","https://api-adresse.data.gouv.fr/"],"default-src":["'self'"],"font-src":["'self'","data:","https:"],"form-action":["'self'"],"frame-ancestors":["'self'"],"img-src":["'self'","https://aie-prod.s3.fr-par.scw.cloud/","data:","https://agents-intervention-prod-uploads.s3.fr-par.scw.cloud/","https://dev-aei.cellar-c2.services.clever-cloud.com/","https://*.jawg.io/","https://aie-dev.s3.fr-par.scw.cloud/","https://agents-intervention-dev-uploads.s3.fr-par.scw.cloud/"],"object-src":["'none'"],"script-src":["'unsafe-inline'","'self'"],"script-src-attr":["'none'"],"style-src":["'unsafe-inline'","'self'","https:"],"upgrade-insecure-requests":["'none'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":true,"defaultNone":false,"insecureBaseUri":false,"insecureFormAction":false,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":true,"unsafeInlineStyle":true,"unsafeObjects":false}},"pass":false,"result":"csp-implemented-with-unsafe-inline","score_description":"Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.","score_modifier":-20},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":null,"clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-not-implemented","score_description":"Content is not visible via cross-origin resource sharing (CORS) files or headers","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://agentsenintervention.anct.gouv.fr/","redirects":false,"route":["http://agentsenintervention.anct.gouv.fr/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":"no-referrer","http":true,"meta":false},"pass":true,"result":"referrer-policy-private","score_description":"Referrer-Policy header set to \"no-referrer\", \"same-origin\", \"strict-origin\" or \"strict-origin-when-cross-origin\"","score_modifier":5},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=15552000; includeSubDomains","includeSubDomains":true,"max-age":15552000,"preload":false,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-but-all-scripts-loaded-from-secure-origin","score_description":"Subresource Integrity (SRI) not implemented, but all scripts are loaded from a similar origin","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"SAMEORIGIN"},"pass":true,"result":"x-frame-options-implemented-via-csp","score_description":"X-Frame-Options (XFO) implemented via the CSP frame-ancestors directive","score_modifier":5},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":"0"},"pass":false,"result":"x-xss-protection-disabled","score_description":"X-XSS-Protection header set to \"0\" (disabled)","score_modifier":-10}}} \ No newline at end of file +{"url":"https://agentsenintervention.anct.gouv.fr/","algorithm_version":2,"end_time":"Sun, 17 Dec 2023 02:41:35 GMT","grade":"C","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"cache-control":"s-maxage=31536000, stale-while-revalidate","content-encoding":"gzip","content-security-policy":"default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data: https://agents-intervention-prod-uploads.s3.fr-par.scw.cloud/ https://agents-intervention-dev-uploads.s3.fr-par.scw.cloud/ https://aie-prod.s3.fr-par.scw.cloud/ https://aie-dev.s3.fr-par.scw.cloud/ https://dev-aei.cellar-c2.services.clever-cloud.com/ https://*.jawg.io/;object-src 'none';script-src 'self' 'unsafe-inline';script-src-attr 'none';connect-src 'self' https://api-adresse.data.gouv.fr/ https://agentsenintervention.anct.gouv.fr/api;style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests","content-type":"text/html; charset=utf-8","cross-origin-opener-policy":"same-origin","cross-origin-resource-policy":"same-origin","date":"Sun, 17 Dec 2023 02:41:33 GMT","etag":"\"4pmw05uh681hgl\"","origin-agent-cluster":"?1","referrer-policy":"no-referrer","server":"envoy","strict-transport-security":"max-age=15552000; includeSubDomains","transfer-encoding":"chunked","vary":"RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Url, Accept-Encoding","x-content-type-options":"nosniff","x-dns-prefetch-control":"off","x-download-options":"noopen","x-envoy-upstream-service-time":"21","x-frame-options":"SAMEORIGIN","x-nextjs-cache":"HIT","x-permitted-cross-domain-policies":"none","x-xss-protection":"0"},"scan_id":45538173,"score":50,"start_time":"Sun, 17 Dec 2023 02:41:31 GMT","state":"FINISHED","status_code":200,"tests_failed":3,"tests_passed":9,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"base-uri":["'self'"],"connect-src":["'self'","https://api-adresse.data.gouv.fr/","https://agentsenintervention.anct.gouv.fr/api"],"default-src":["'self'"],"font-src":["'self'","data:","https:"],"form-action":["'self'"],"frame-ancestors":["'self'"],"img-src":["https://aie-prod.s3.fr-par.scw.cloud/","'self'","https://aie-dev.s3.fr-par.scw.cloud/","data:","https://agents-intervention-prod-uploads.s3.fr-par.scw.cloud/","https://dev-aei.cellar-c2.services.clever-cloud.com/","https://agents-intervention-dev-uploads.s3.fr-par.scw.cloud/","https://*.jawg.io/"],"object-src":["'none'"],"script-src":["'unsafe-inline'","'self'"],"script-src-attr":["'none'"],"style-src":["'unsafe-inline'","'self'","https:"],"upgrade-insecure-requests":["'none'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":true,"defaultNone":false,"insecureBaseUri":false,"insecureFormAction":false,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":true,"unsafeInlineStyle":true,"unsafeObjects":false}},"pass":false,"result":"csp-implemented-with-unsafe-inline","score_description":"Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.","score_modifier":-20},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":null,"clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-not-implemented","score_description":"Content is not visible via cross-origin resource sharing (CORS) files or headers","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://agentsenintervention.anct.gouv.fr/","redirects":false,"route":["http://agentsenintervention.anct.gouv.fr/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":"no-referrer","http":true,"meta":false},"pass":true,"result":"referrer-policy-private","score_description":"Referrer-Policy header set to \"no-referrer\", \"same-origin\", \"strict-origin\" or \"strict-origin-when-cross-origin\"","score_modifier":5},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=15552000; includeSubDomains","includeSubDomains":true,"max-age":15552000,"preload":false,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-but-all-scripts-loaded-from-secure-origin","score_description":"Subresource Integrity (SRI) not implemented, but all scripts are loaded from a similar origin","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"SAMEORIGIN"},"pass":true,"result":"x-frame-options-implemented-via-csp","score_description":"X-Frame-Options (XFO) implemented via the CSP frame-ancestors directive","score_modifier":5},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":"0"},"pass":false,"result":"x-xss-protection-disabled","score_description":"X-XSS-Protection header set to \"0\" (disabled)","score_modifier":-10}}} \ No newline at end of file diff --git a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/lhr-aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv.html b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/lhr-aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv.html index 66178a2c5c..f9ad3a0c81 100644 --- a/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/lhr-aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv.html +++ b/results/aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv/lhr-aHR0cHM6Ly9hZ2VudHNlbmludGVydmVudGlvbi5hbmN0LmdvdXYuZnIv.html @@ -28,7 +28,7 @@
- +