Content Security Policy connect-src
-
It appears you have added new connect sources for your service and I need a list of them so that I can update all of my content security policies. Currently I allow https://fd.cleantalk.org/ and https://fd-v4.cleantalk.org/ but have started to see https://fd-v6.cleantalk.org/. Due to PCI compliance I do not want to wildcard this. Is there a location where you maintain all of the different scripts and sources that I can access? Also, is there a way that we can get notified when you change the urls so that we are not bombarded with error in your CPS logs?
Here is a sample of the items I currently allow.
script-src https://fd.cleantalk.org/ https://moderate.cleantalk.org/;
connect-src https://fd.cleantalk.org/ https://fd-v4.cleantalk.org/ https://moderate.cleantalk.org/;
You must be logged in to reply to this topic.