Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Relax the report-only CSP connect-src directive (#4390)
Google analytics may wish to connect with any of 187 different top-level domains, which would be very long and annoying to maintain. See https://developers.google.com/tag-platform/security/guides/csp#google_analytics_4_google_analytics Rather than explicitly allow each one of those 187 different domains, this commit just allows connecting to any domain as long as it uses https.
- Loading branch information