-
Notifications
You must be signed in to change notification settings - Fork 38
Interpret and filter CSP reports #1118
Comments
They all use the https://sentry.io/gratipay/gratipay-com/?query=logger%3A%22csp%22 |
Worst addressed in gratipay/gratipay.com#4552. |
I've turned off notifications (slack/email) for |
Sorta defeats the purpose, but understandable for now. 😛 |
gratipay/gratipay.com#4552 doesn't solve the How is the hash computed, I wonder? |
Ah! We have variable URLs in there, for assets.
|
Lol, and etags, so it's variable per-deploy. 🙈 |
Alright, back to the drawing board. 😛 |
@/mattrobenolt suggests (IRL at PyOhio) that we send CSP reports to a separate project for better filterability. |
With gratipay/gratipay.com#4542 we are now sending CSP reports to Sentry, which makes them much more visible. That's great! But there's a lot of them. What do they mean? How should we process them?
The text was updated successfully, but these errors were encountered: