Skip to content

Add guidance for Content-Security-Policy#107

Merged
levinmr merged 1 commit intodigital-analytics-program:masterfrom
levinmr:master
May 3, 2024
Merged

Add guidance for Content-Security-Policy#107
levinmr merged 1 commit intodigital-analytics-program:masterfrom
levinmr:master

Conversation

@levinmr
Copy link
Copy Markdown
Contributor

@levinmr levinmr commented Apr 29, 2024

No description provided.

@raybaxter
Copy link
Copy Markdown

This guidance is insufficient for a working implementation.

Universal-Federated-Analytics injects a script tag with src "https://www.google-analytics.com/analytics.js" without including the nonce and initiates at least 2 POST requests to https://www.google-analytics.com/.

@levinmr
Copy link
Copy Markdown
Contributor Author

levinmr commented Apr 30, 2024

This guidance is insufficient for a working implementation.

Universal-Federated-Analytics injects a script tag with src "https://www.google-analytics.com/analytics.js" without including the nonce and initiates at least 2 POST requests to https://www.google-analytics.com/.

You're right. I've updated the guidance to be more accurate.

@levinmr
Copy link
Copy Markdown
Contributor Author

levinmr commented Apr 30, 2024

@raybaxter please review

@levinmr levinmr merged commit d0669ae into digital-analytics-program:master May 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants