Skip to content

[Issue] 'Report-To' header is deprecated and no longer recommended #39288

Open
@m2-assistant

Description

@m2-assistant

This issue is automatically created based on existing pull request: #39278: 'Report-To' header is deprecated and no longer recommended


Description (*)

As reported in this document, 'Report-To' header is deprecated and no longer recommended to report CSP violations.
And, in any case, it is not possible to add "report-to " in the 'Content-Security-Policy-Report-Only' header.

Manual testing scenarios (*)

  1. Set CSP in "report-only"
  2. Compile 'Report URI' fields in Configuration > Security > Content Security Policy (CSP) page
  3. Navigate the website in a page that contains some CSP violations
  4. It must be a POST call to Report URI.

Contribution checklist (*)

  • Pull request has a meaningful description of its purpose
  • All commits are accompanied by meaningful commit messages
  • All new or changed code is covered with unit/integration tests (if applicable)
  • README.md files for modified modules are updated and included in the pull request if any README.md predefined sections require an update
  • All automated tests passed successfully (all builds are green)

Metadata

Metadata

Assignees

Labels

Area: FrameworkComponent: CspIssue: ConfirmedGate 3 Passed. Manual verification of the issue completed. Issue is confirmedPriority: P2A defect with this priority could have functionality issues which are not to expectations.Progress: PR in progressReported on 2.4.xIndicates original Magento version for the Issue report.Reproduced on 2.4.xThe issue has been reproduced on latest 2.4-develop branch

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions