Project

General

Profile

Actions

User story #26951

closed

User story #26934: Enable CSP on all pages and add tag to exclude a page

Plugins need CSP to be strict in Rudder but disabled in plugin pages

Added by Clark ANDRIANASOLO 2 months ago. Updated 8 days ago.

Status:
Released
Priority:
N/A
Category:
Web - Maintenance
Target version:
UX impact:
Suggestion strength:
User visibility:
First impressions of Rudder
Effort required:
Small
Name check:
To do
Fix check:
To do
Regression:
No

Description

In parent, strict CSP headers are enabled on all pages and need to be present for scripts added by some plugins, e.g. to display something from the plugin the login page, or in the navbar.

But the plugins pages themselves have additional pages, which can be later migrated to include CSP headers


Related issues 1 (0 open1 closed)

Related to API authorizations - Bug #27314: CSP violation in api accounts custom ACL selectionReleasedVéronique HAYAERTActions
Actions

Also available in: Atom PDF