Skip to content

Conversation

soberm
Copy link
Contributor

@soberm soberm commented Aug 20, 2025

Description of changes:

Update CSP configuration to not use wildcards.

  • Removed *.amazonaws.com as it is a leftover from when we called a Lambda directly for submitting feedback.
  • Changed https://*.algolia.net https://*.algolianet.com to use the specific URLs including the ALGOLIA_APP_ID.
  • Changed *.shortbread.aws.dev to 'https://prod.tools.shortbread.aws.dev' 'https://prod.log.shortbread.aws.dev' 'https://prod.assets.shortbread.aws.dev'

Related GitHub issue #, if available:

Instructions

If this PR should not be merged upon approval for any reason, please submit as a DRAFT

Which product(s) are affected by this PR (if applicable)?

  • amplify-cli
  • amplify-ui
  • amplify-studio
  • amplify-hosting
  • amplify-libraries

Which platform(s) are affected by this PR (if applicable)?

  • JS
  • Swift
  • Android
  • Flutter
  • React Native

Please add the product(s)/platform(s) affected to the PR title

Checks

  • Does this PR conform to the styleguide?

  • Does this PR include filetypes other than markdown or images? Please add or update unit tests accordingly.

  • Are any files being deleted with this PR? If so, have the needed redirects been created?

  • Are all links in MDX files using the MDX link syntax rather than HTML link syntax?

    ref: MDX: [link](https://docs.amplify.aws/)
    HTML: <a href="https://docs.amplify.aws/">link</a>

When this PR is ready to merge, please check the box below

  • Ready to merge

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@soberm soberm requested a review from a team as a code owner August 20, 2025 15:06
@soberm soberm merged commit c76c70e into main Aug 21, 2025
12 checks passed
@soberm soberm deleted the fix/csp_violation branch August 21, 2025 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants