Skip to content

Commit d012c53

Browse files
Allow eu-assets.i.posthog.com
1 parent 26f33aa commit d012c53

File tree

2 files changed

+14
-5
lines changed

2 files changed

+14
-5
lines changed

pkg/lib/web/csp.go

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -158,6 +158,10 @@ var wwwgoogletagmanagercom = CSPHostSource{
158158
Host: "www.googletagmanager.com",
159159
}
160160

161+
var euassetsiposthogcom = CSPHostSource{
162+
Host: "eu-assets.i.posthog.com",
163+
}
164+
161165
var cdnjscloudflarecom = CSPHostSource{
162166
Host: "cdnjs.cloudflare.com",
163167
}
@@ -202,10 +206,15 @@ func CSPDirectives(opts CSPDirectivesOptions) ([]string, error) {
202206
},
203207
}
204208
}
205-
scriptSrc = append(scriptSrc, wwwgoogletagmanagercom, CSPHostSource{
206-
Scheme: "https",
207-
Host: "browser.sentry-cdn.com",
208-
})
209+
scriptSrc = append(
210+
scriptSrc,
211+
wwwgoogletagmanagercom,
212+
euassetsiposthogcom,
213+
CSPHostSource{
214+
Scheme: "https",
215+
Host: "browser.sentry-cdn.com",
216+
},
217+
)
209218
scriptSrc = append(scriptSrc, baseSrc...)
210219
sort.Sort(scriptSrc)
211220

pkg/portal/routes.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ func NewRouter(p *deps.RootProvider) *httproute.Router {
2828
// ES6 module assumes strict mode.
2929
// regeneratorRuntime is not compatible with strict mode because
3030
// it uses Function to generate function, which is considered as eval.
31-
"script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.jsdelivr.net unpkg.com www.googletagmanager.com cdn.mxpnl.com eu.posthog.com cmp.osano.com",
31+
"script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.jsdelivr.net unpkg.com www.googletagmanager.com cdn.mxpnl.com eu.posthog.com eu-assets.i.posthog.com cmp.osano.com",
3232
// monaco editor create worker with blob:
3333
"worker-src 'self' 'unsafe-inline' cdn.jsdelivr.net blob:",
3434
"object-src 'none'",

0 commit comments

Comments
 (0)