Skip to content

Commit 1f32292

Browse files
authored
nginx: use Reporting-Endpoints header to set report-to (#61)
- also set report-uri until Firefox supports report-to
1 parent 9840ee8 commit 1f32292

File tree

3 files changed

+6
-3
lines changed

3 files changed

+6
-3
lines changed

modules/profile/templates/contentorigin/site.nginx.erb

+2-1
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,8 @@ server {
1414
server_tokens off;
1515

1616
# Add Content Security Policy headers
17-
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self'; report-to https://csp-report-api.openjs-foundation.workers.dev/";
17+
add_header Reporting-Endpoints "csp-endpoint=\"https://csp-report-api.openjs-foundation.workers.dev/\""
18+
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri https://csp-report-api.openjs-foundation.workers.dev/; report-to csp-endpoint";
1819

1920
location / {
2021
root /srv/www/content.jquery.com;

modules/profile/templates/gruntjscom/site.nginx.erb

+2-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,8 @@ server {
1818
proxy_buffering off;
1919

2020
# Add Content Security Policy headers
21-
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self'; report-to https://csp-report-api.openjs-foundation.workers.dev/" always;
21+
add_header Reporting-Endpoints "csp-endpoint=\"https://csp-report-api.openjs-foundation.workers.dev/\""
22+
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri https://csp-report-api.openjs-foundation.workers.dev/; report-to csp-endpoint;" always;
2223
}
2324

2425
location /.well-known/acme-challenge {

modules/profile/templates/miscweb/site.nginx.erb

+2-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,8 @@ server {
1919
root /srv/www/<%= @fqdn %><%= @site['webroot'] or '' %>;
2020

2121
# Add Content Security Policy headers
22-
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self'; report-to https://csp-report-api.openjs-foundation.workers.dev/";
22+
add_header Reporting-Endpoints "csp-endpoint=\"https://csp-report-api.openjs-foundation.workers.dev/\""
23+
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri https://csp-report-api.openjs-foundation.workers.dev/; report-to csp-endpoint";
2324

2425
<%- if @site['allow_php'] -%>
2526
index index.php index.html;

0 commit comments

Comments
 (0)