Repository navigation
fix(csp): allow Cloudflare Insights beacon in script-src/connect-src - #1788
Conversation
Cloudflare auto-injects static.cloudflareinsights.com/beacon.min.js; the CSP script-src 'self' blocked it, generating steady csp-report noise (Sentry LUCKY-46). Allowlist the beacon host in script-src and its telemetry origin in connect-src, in both the frontend _headers and the backend helmet CSP. Closes #1782
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 4 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Failed to generate code suggestions for PR |
There was a problem hiding this comment.
1 issue found across 2 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="packages/frontend/public/_headers">
<violation number="1" location="packages/frontend/public/_headers:5">
P3: `connect-src` addition of `https://cloudflareinsights.com` is unnecessary for auto-injected Cloudflare Web Analytics. Per Cloudflare docs, the proxied site's beacon POSTs to `/cdn-cgi/rum` on the same origin, already covered by `'self'`. The `cloudflareinsights.com` origin only applies to manual embedding (JS snippet on non-proxied sites), which this codebase doesn't use. Consider dropping it from `connect-src` to keep the CSP minimal.</violation>
</file>
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
|
Size Change: 0 B Total Size: 494 kB ℹ️ View Unchanged
|
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Auto-approved: CSP config update to allow Cloudflare Insights script-src. Low-risk, no logic changes.
Re-trigger cubic
|
🤖 I have created a release *beep* *boop* --- <details><summary>2.35.0</summary> ## [2.35.0](v2.34.0...v2.35.0) (2026-07-13) ### Features * **bot:** /bulk-kick — proof-of-pattern for the bulk-* command family ([#1802](#1802)) ([1c11f3e](1c11f3e)) * **bot:** add lucky_bot_gateway_connected zombie-detection gauge ([#1774](#1774)) ([6cc5287](6cc5287)) * **bot:** playback progress bar in nowplaying/songinfo embed ([#1797](#1797)) ([1138b59](1138b59)) * **bot:** post server-count stats to Top.gg for listing visibility ([#1789](#1789)) ([e8ca6b9](e8ca6b9)) * **bot:** temporary support ticket channels (/ticket) ([#1803](#1803)) ([49601a1](49601a1)) * **live-notif:** youtube polling, message ttl cleanup, api backoff ([#1762](#1762)) ([a99b85a](a99b85a)) * **remind:** channel and role broadcast reminders ([#1767](#1767)) ([#1807](#1807)) ([83ade79](83ade79)) ### Bug Fixes * **backend:** artist suggestions 503 not 500 on upstream timeout ([#1787](#1787)) ([eadc20e](eadc20e)) * **bot:** guard skipReason telemetry against null prisma client ([#1773](#1773)) ([d73421e](d73421e)) * **ci:** stop auto-update workflow racing on merge push ([#1811](#1811)) ([2ddd202](2ddd202)) * **csp:** allow Cloudflare Insights beacon in script-src/connect-src ([#1788](#1788)) ([f20c4cf](f20c4cf)) * **deps:** bump eslint in lock to satisfy npm@12 ci (unblock release) ([#1809](#1809)) ([68fd0be](68fd0be)) * paginate bulk-move message fetch to respect discord api limit ([#1776](#1776)) ([5b5d2fc](5b5d2fc)) * **weekly-digest:** trigger on Sunday and add new-guides RSS section ([#1761](#1761)) ([f429fc6](f429fc6)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).



Fixes the most frequent Sentry error (LUCKY-46, 22+ events): CSP
script-src 'self'blocked Cloudflare's auto-injectedstatic.cloudflareinsights.com/beacon.min.js, producing continuousPOST /api/security/csp-reportnoise.Adds
https://static.cloudflareinsights.comtoscript-srcandhttps://cloudflareinsights.com(beacon telemetry origin) toconnect-src, in bothpackages/frontend/public/_headersand the backend helmet CSP (packages/backend/src/middleware/index.ts). Config-only; type:check + eslint clean.Closes #1782
Summary by cubic
Allow Cloudflare Insights by adding
static.cloudflareinsights.comtoscript-srcin frontend headers and backendhelmetCSP. Unblocks the auto-injected beacon and reduces Sentry CSP report noise; closes #1782.https://static.cloudflareinsights.comtoscript-srcinpackages/frontend/public/_headersandpackages/backend/src/middleware/index.ts.connect-srcchanges.Written for commit 2a7af68. Summary will update on new commits.