【问题标题】:CDN on Azure App Services - possible to have Content-Security-Policy-Report-Only header?Azure App Services 上的 CDN - 可能有 Content-Security-Policy-Report-Only 标头?
【发布时间】:2021-12-18 20:48:15
【问题描述】:

是否可以在 Azure 应用服务的 CDN 上实现 Content-Security-Policy-Report-Only 的标头?

我无法使用空白值添加它,并且如果我添加对 Content-Security-Policy 有效的值,例如那么它也失败了。

【问题讨论】:

    标签: azure-web-app-service cdn content-security-policy


    【解决方案1】:

    如果我添加一个对 Content-Security-Policy 有效的值,例如那么它也失败了。

    Content-Security-Policy-Report-Only 标头应该有一个强制性的report-uri 或report-to 指令,否则它将在控制台中显示一个警告,表明您的标头什么都不做。

    Content-Security-Policy-Report-Only 标头不会阻止,只是发送有关阻止某些内容的意图的报告。因此,您可以找出遗漏的来源并将其添加到适当的指令中。
    您可以使用 starter CSP,例如:

    default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; report-uri https://YourReportHandler.com/csp-endpoint
    

    然后检查违规报告并将被阻止的源添加到启动 CSP。

    注意。要处理违规报告,您可以使用raygun.com / report-uri.com 和类似的第三方服务或自行处理 CSP 报告,例如 Save reports to Azure Table storage。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2018-09-05
      • 2013-05-03
      • 1970-01-01
      • 2022-01-21
      • 1970-01-01
      • 2018-05-04
      • 1970-01-01
      • 2013-01-13
      相关资源
      最近更新 更多