Skip to content

Commit

Permalink
Merge pull request #334 from alphagov/add-assets-domain-to-script-csp
Browse files Browse the repository at this point in the history
Add GOVUK domains to script src CSP
  • Loading branch information
AshGDS authored Dec 20, 2023
2 parents 6639ba2 + d3ed92c commit bba0e4b
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 1 deletion.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# 9.8.0

* Add GOVUK domains to script src CSP ([#334](https://github.com/alphagov/govuk_app_config/pull/334))

# 9.7.0

* Enable adding custom LogStasher fields from apps ([#327](https://github.com/alphagov/govuk_app_config/pull/327))
Expand Down
1 change: 1 addition & 0 deletions lib/govuk_app_config/govuk_content_security_policy.rb
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,7 @@ def self.build_policy(policy)
policy.script_src :self,
*GOOGLE_ANALYTICS_DOMAINS,
*GOOGLE_STATIC_DOMAINS,
*GOVUK_DOMAINS,
# Allow YouTube Embeds (Govspeak turns YouTube links into embeds)
"*.ytimg.com",
"www.youtube.com",
Expand Down
2 changes: 1 addition & 1 deletion lib/govuk_app_config/version.rb
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
module GovukAppConfig
VERSION = "9.7.0".freeze
VERSION = "9.8.0".freeze
end

0 comments on commit bba0e4b

Please sign in to comment.