Skip to content

Commit bfa5767

Browse files
authored
fix: add Google Analytics regional domains to CSP connect-src (#109)
Google Analytics uses regional subdomains (e.g. region1.google-analytics.com) for data collection. Add wildcard and googletagmanager.com to connect-src.
1 parent 7339f08 commit bfa5767

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_includes/head.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
<meta http-equiv="Referrer-Policy" content="no-referrer, strict-origin-when-cross-origin">
1010

1111
<meta http-equiv='Content-Security-Policy'
12-
content="default-src https://www.youtube.com https://www.google-analytics.com; style-src 'self' https://cdnjs.cloudflare.com; img-src 'self' https://static.jboss.org https://www.google-analytics.com; font-src 'self' https://cdnjs.cloudflare.com; script-src 'self' https://maxcdn.bootstrapcdn.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://www.apicurio.io https://www.googletagmanager.com https://apicurio-support-chat.onrender.com; connect-src 'self' https://www.google-analytics.com https://apicurio-support-chat.onrender.com; frame-ancestors 'none'; base-uri 'none'; form-action 'none';">
12+
content="default-src https://www.youtube.com https://www.google-analytics.com; style-src 'self' https://cdnjs.cloudflare.com; img-src 'self' https://static.jboss.org https://www.google-analytics.com; font-src 'self' https://cdnjs.cloudflare.com; script-src 'self' https://maxcdn.bootstrapcdn.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://www.apicurio.io https://www.googletagmanager.com https://apicurio-support-chat.onrender.com; connect-src 'self' https://www.google-analytics.com https://*.google-analytics.com https://www.googletagmanager.com https://apicurio-support-chat.onrender.com; frame-ancestors 'none'; base-uri 'none'; form-action 'none';">
1313

1414
<link rel="shortcut icon" href="{{ site.baseurl }}/images/favicon.ico" type="image/x-icon" integrity="sha384-if9KH+NQ2dMhdrWu+INnJTcvG6riRakUAnbhecX5a7voubrapo7ouFGS+GYZ/N4P" crossorigin="anonymous"/>
1515

0 commit comments

Comments
 (0)