Page MenuHomePhabricator

Set strict CSP rule on Kibana logstash.wikimedia.org
Open, Needs TriagePublic

Description

Can we set a hard CSP on this domain at the web server level so that in general our report will be "oh no, there's a request attempt we didn't notice" (possibly with a "hm.. and feature X is partly not working as a result") - as opposed to "oh no, we're actually making requests we don't want."

Event Timeline