Repository navigation
security: Content-Security-Policy (report-only) + /api/csp-report - #174
Merged
Merged
Conversation
…report Adds a Content-Security-Policy-Report-Only header (plus Reporting-Endpoints) built from what the app actually loads (Next inline scripts, gtag, Mapbox, Supabase https/wss, Google Maps/Places/GIS, Chart.js CDN, Luma iframes, Vercel toolbar). Violations POST to /api/csp-report, which accepts both application/csp-report and application/reports+json, caps bodies at 10KB, strips query strings, and logs compact [csp] lines via console.warn. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Content-Security-Policy-Report-Onlyheader (andReporting-Endpoints) innext.config.tsheaders(), next to the existing security headers. Nothing gets blocked. Browsers only report violations.POST /api/csp-report, which acceptsapplication/csp-report(fromreport-uri) andapplication/reports+json(fromreport-to). It rejects other content types (415) and bodies over 10KB (413, checked from Content-Length and again while streaming). It parses at most 10 reports, cuts each field to 200 chars and removes query strings from URLs, then logs one compact[csp] {...}line per violation viaconsole.warn. There are no DB writes.src/lib/__tests__/csp-report.test.ts.Policy
Why the less obvious entries are there:
'unsafe-inline'scripts: Next's inline bootstrap and RSC payload, the theme script and JSON-LD inlayout.tsx, and the inline gtag config. Using nonces would mean adding a proxy and rendering every page dynamically, so that is left for later.www.google.com: GA4 sends its/g/collectbeacons there.cdn.jsdelivr.net: Chart.js on/admin/analytics.vercel.liveand pusher: the Vercel toolbar on preview deployments.Verification
next build && next startwith Playwright (Chromium) and collected[Report Only]console messages on://kbw2026in Map, List, Table and Gallery views (scrolled)/kbw2026with the sign-in modal open/itinerary,/admin,/admin/analytics,/sponsors,/orgswww.google.com, which are now allowed. Final pass: 0 violations.[csp]lines, a 20KB body (plain and chunked) returns 413, andtext/plainreturns 415.npx tsc --noEmitpasses.npm testpasses (286 tests).Rollout plan
[csp]lines. Add legitimate sources to the policy, and ignore noise from browser extensions (chrome-extension:,moz-extension:, etc.).next.config.tsfromContent-Security-Policy-Report-OnlytoContent-Security-Policyto enforce it. Keep the reporting directives.script-srcwith nonces or hashes to remove'unsafe-inline'.🤖 Generated with Claude Code