Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

is Daum Postal Service API supporting Content-Security-Policy webpage #637

Open
gshwe opened this issue Jul 21, 2020 · 4 comments
Open

is Daum Postal Service API supporting Content-Security-Policy webpage #637

gshwe opened this issue Jul 21, 2020 · 4 comments
Labels

Comments

@gshwe
Copy link

gshwe commented Jul 21, 2020

Hi Sir/Madam,

Question is related to Daum Postal Service API able to support and function as normal from a website which have the Content-Security-Policy option turn on, with *.daumcdn.net domain included under policy attribute script-src, style-src, font-src, img-src, connect-src and frame-src? is the guide from https://spi.maps.daum.net/postcode/guidessl able to provide more information on what need to do in html page if Content-Security-Policy require turn on?

Reason asking is because my tested result will show an empty pop-up content when Content-Security-Policy turn on.

Regards,

@daumPostcode
Copy link
Owner

@gshwe
hello gshwe

The Daum Postcode service uses multiple domains, not one domain.
If you are using CSP, please register all domains used by the postal code service.

HTTP :

HTTPS :

Thank you.

@gshwe
Copy link
Author

gshwe commented Jul 23, 2020

Thanks daumPostcode.

The information is very helpful. after put in the addional 3 domains, the pop-up is working fine with Security Rating as A.

I hope this information can be included in your guide for any domain who will need to turn on the Content-Security-Policy setting.

Thank You.

@daumPostcode
Copy link
Owner

@gshwe

Yes, I will apply it to the guide page.
Thank you for your suggestion.

@gshwe
Copy link
Author

gshwe commented Jul 23, 2020

for your reference, this is the site where I used on checking the Security rating. https://securityheaders.com/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants