Project

General

Profile

Actions

Feature #105087

open

CSP Header option to disable or reduce amount of reporting-uri requests

Added by Sascha Zander about 2 months ago. Updated about 1 month ago.

Status:
Needs Feedback
Priority:
Should have
Assignee:
-
Category:
Content Security Policy
Start date:
2024-09-23
Due date:
% Done:

0%

Estimated time:
PHP Version:
8.2
Tags:
csp
Complexity:
Sprint Focus:

Description

Hi,

I couldn't find a way to render the CSP headers without the reporting-uri.

The problem is that we have a lot of thirdparty javascripts on the page.
As soon as we have a new CSP error, our network load doubles every time due to the reporting request of the clients.

It would be better if the reporting-uri would only be attached for logged in backend users or to have an option to turn it off completely.

Actions

Also available in: Atom PDF