fix: allowing csp for intra domain communication #1079
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
List of Changes
Allowed https://.dev.developer.pagopa.it in dev environment's csp
Allowed https://.developer.pagopa.it in prod environment's csp
Motivation and Context
The chatbot UI could not reach the backend APIs with the following error:
Refused to connect to 'https://api.chatbot.dev.developer.pagopa.it/queries' because it violates the following Content Security Policy directive: "connect-src 'self' https://cognito-identity.eu-south-1.amazonaws.com/ https://dynamodb.eu-south-1.amazonaws.com/ https://cognito-idp.eu-south-1.amazonaws.com/ https://raw.githubusercontent.com/pagopa/ https://raw.githubusercontent.com/teamdigitale/ https://*.cookielaw.org https://*.onetrust.com https://www.google-analytics.com/ https://api.io.italia.it/ *.google-analytics.com https://pagopa.matomo.cloud/".
How Has This Been Tested?
Screenshots (if appropriate):
Types of changes
Checklist: