adopted-ember-addons / adopted-ember-addons/ember-cli-content-security-policy

Use report-to instead of the deprecated report-uri

オープン
#166 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement good first issue
主要言語
JavaScript
スター
157
フォーク
44
PR マージ指標
30日以内にマージされた PR はありません

説明

The new Reporting API is not supported by all browsers yet, so **this isn't something we need to move on for at least another year or so**. As of November 2020 it's not yet supported by Firefox or Safari.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-to

1. At some point we'll want to add support for `report-to` in addition to `report-uri`. With both are present and the browser support both, `report-to` takes precedence.
2. Separately, when all browsers supported by ember has support for `report-to` we'll want to drop the `report-uri` value.

Opened since @jelhan asked me to: https://github.com/rwjblue/ember-cli-content-security-policy/issues/148

**Background**

- https://developers.google.com/web/updates/2018/09/reportingapi
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-uri
- https://www.w3.org/TR/CSP3/

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。