Skip to content

feat: Capture CSP violations - #41

Merged
foxable merged 2 commits into
mainfrom
feat/csp-captor
Sep 24, 2026
Merged

foxable merged 2 commits into
mainfrom
feat/csp-captor

Conversation

@foxable

@foxable foxable commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

CSP violations are usually silent: the browser drops the blocked resource, logs a console warning, and the test still passes. CspCaptor closes that gap by surfacing every violation as structured data.

  • The automatic cspFixtures fixture guards against otherwise undetected CSP violations by failing any test that triggers one, without requiring changes to individual test files.
  • CspCaptor and captureCspViolations can also be used directly, giving tests the ability to trigger and assert on individual CSP directives.

Features

  • CspCaptor: collects a page's securitypolicyviolation events as structured CspViolation objects
  • captureCspViolations: factory for creating a CspCaptor
  • cspFixtures: ready-to-merge Playwright fixtures that install an auto-starting cspCaptor on every test and fail it on unexpected violations, configurable per test via the ignoreCspViolations option fixture

@foxable foxable self-assigned this Sep 22, 2026
@changeset-bot

changeset-bot Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 45bacd1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@cronn/playwright-utils Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@foxable foxable changed the title feat: Add CspCaptor for capturing CSP violations feat: Capture CSP violations Sep 22, 2026
@PMudra
PMudra self-requested a review September 23, 2026 12:09
Comment thread tests/csp-captor.spec.ts
@foxable
foxable merged commit 272aa90 into main Sep 24, 2026
2 checks passed
@foxable
foxable deleted the feat/csp-captor branch September 24, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants