Skip to content

Limit analytics CSP revisions to necessary entries#11021

Merged
aduth merged 3 commits intomainfrom
aduth-dap-csp-ga4
Aug 5, 2024
Merged

Limit analytics CSP revisions to necessary entries#11021
aduth merged 3 commits intomainfrom
aduth-dap-csp-ga4

Conversation

@aduth
Copy link
Copy Markdown
Contributor

@aduth aduth commented Aug 2, 2024

🛠 Summary of changes

Updates content security policy to limit directives to only those strictly necessary for Digital Analytics Program.

See documentation: https://github.com/digital-analytics-program/gov-wide-code#content-security-policy

Since these conflicted with the recommendations from Google for Google Analytics, I had reached out to the DAP support team to clarify that their documented recommendations are sufficient. I'll also plan to monitor this after the changes go live to ensure there are no issues.

📜 Testing Plan

Verify that there are no errors in browser developer tools console when loading the preview site for this branch:

TBD

(It's enabled temporarily in preview environments, but this will be removed prior to merging)

@aduth aduth requested a review from mitchellhenke August 2, 2024 13:55
@aduth aduth force-pushed the aduth-dap-csp-ga4 branch from ae5819a to 5e2c65a Compare August 2, 2024 22:19
@aduth
Copy link
Copy Markdown
Contributor Author

aduth commented Aug 5, 2024

I'm having difficulty with the review apps, so I'll just plan to test this in staging and revert if necessary.

@aduth aduth merged commit 2d0332b into main Aug 5, 2024
@aduth aduth deleted the aduth-dap-csp-ga4 branch August 5, 2024 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants