Yesterday when investigating T422829: Toolforge HTML head links sometimes are issued as http://<tool>.toolforge:443 I noticed and learned about csp-report which is awesome. My browser sent the following report, though I could not find it on https://csp-report.toolforge.org/search?ft=sal
{
"blocked-uri": "http://sal.toolforge.org:443/assets/main.css",
"disposition": "report",
"document-uri": "https://sal.toolforge.org/admin?p=0&q=&d=2026-03-13",
"effective-directive": "style-src-elem",
"original-policy": "default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: filesystem: mediastream: *.toolforge.org wikibooks.org *.wikibooks.org wikidata.org *.wikidata.org wikimedia.org *.wikimedia.org wikinews.org *.wikinews.org wikipedia.org *.wikipedia.org wikiquote.org *.wikiquote.org wikisource.org *.wikisource.org wikiversity.org *.wikiversity.org wikivoyage.org *.wikivoyage.org wiktionary.org *.wiktionary.org *.wmcloud.org *.wmflabs.org wikimediafoundation.org mediawiki.org *.mediawiki.org wss://sal.toolforge.org; report-uri https://csp-report.toolforge.org/collect;",
"referrer": "https://sal.toolforge.org/admin",
"script-sample": "",
"status-code": 200,
"violated-directive": "style-src-elem"
}I don't know if things are working as intended or not, I thought I'd report (hah!) it