adopted-ember-addons / adopted-ember-addons/ember-cli-content-security-policy

Use report-to instead of the deprecated report-uri

Aperta
#166 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
enhancement good first issue
Lingua principale
JavaScript
Stelle
157
Fork
44
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

The new Reporting API is not supported by all browsers yet, so **this isn't something we need to move on for at least another year or so**. As of November 2020 it's not yet supported by Firefox or Safari.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-to

1. At some point we'll want to add support for `report-to` in addition to `report-uri`. With both are present and the browser support both, `report-to` takes precedence.
2. Separately, when all browsers supported by ember has support for `report-to` we'll want to drop the `report-uri` value.

Opened since @jelhan asked me to: https://github.com/rwjblue/ember-cli-content-security-policy/issues/148

**Background**

- https://developers.google.com/web/updates/2018/09/reportingapi
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-uri
- https://www.w3.org/TR/CSP3/

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.