Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-15201

Bootstrap cdn.segment.com to default CSP configuration

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • 15.1.4
    • 15.2.3
    • None
    • None
    • Clean archetpye
    • Nova
    • Nova Sprint 308
    • Small (1-2)

    Description

      The default CSP policy is blocking some tracking code in the CMS. This error shows up in the browser console:

      Content Security Policy: The page's settings blocked the loading of a resource at http://cdn.segment.com/analytics.js/v1/4EIM9QDTm7iYX00nN45ve7VguRGgq1DS/analytics.min.js ("script-src").

      The fix for this should to add cdn.segment.com to the script-src property below /hippo:configuration/hippo:modules/application-settings/hippo:moduleconfig/content-security-policy, but this domain should be bootstrapped in the CSP configuration.

      Attachments

        Activity

          People

            Unassigned Unassigned
            david.bailey David Bailey
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: