You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Content Security Policy supports reporting of violations (see here).
Discussion
No response
Motivation
The Reporting-Endpoints response header can be used e.g. for Content Security Policy violation reports (see here).
Details
Setting the complete reporting endpoint url in the CSP report-to directive did not work (at least in Chrome) althoug some examples on MDN are using them.
As a workaround we are setting the Reporting-Endpoints response header in our application gateway, but it would be much simpler to configure CSP and Reporting-Endpoints in one place.