LG-9740 Add csp overrides for ThreatMetrix before_action to SsnController#8367
Merged
soniaconnolly merged 2 commits intomainfrom May 10, 2023
Merged
LG-9740 Add csp overrides for ThreatMetrix before_action to SsnController#8367soniaconnolly merged 2 commits intomainfrom
soniaconnolly merged 2 commits intomainfrom
Conversation
This before action is needed to allow ThreatMetrix to load in browsers that respect Content Security Policies. It was part of the Flow State Machine but not clearly part of the SSN step. changelog: Bug Fixes, Identity Verification, include Content Security Policy overrides for ThreatMetrix
jmhooper
approved these changes
May 9, 2023
This makes it more explicit that the overrides are required for the SSN step. Co-authored-by: Douglas Price <douglas.price@gsa.gov>
matthinz
approved these changes
May 10, 2023
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎫 Ticket
LG-9740
🛠 Summary of changes
This before action is needed to allow ThreatMetrix to load in browsers that respect Content Security Policies. It was part of the Flow State Machine but not clearly part of the SSN step.
Note: The in_person_controller still uses
override_csp_for_threat_metrixwith the parameter check for the ssn step, so I factored out the main part of the code and made a new method for the remote SsnController. This can be restored to a single method when the in_person FSM SsnStep is removed.Note2: We need a test that checks that ThreatMetrix is loading without errors, either as part of this PR or as a separate PR.
📜 Testing Plan