Skip to content

Releases: markuspat2/csp-reporting-plugin

Release list

v2.1.0

Choose a tag to compare

@github-actions github-actions released this 21 Jul 18:30

Tuning pass driven by the first live deployment.

Fixed

  • Deduplication was defeated by per-request query strings (scanner tokens,
    ?ver= cache-busters): one violation pattern created a new row per
    crawled URL. Hashes are now computed on URLs normalized to
    scheme://host/path, and the upgrade migration merges existing duplicate
    rows (hit counts summed, first/last-seen widened).

Changed

  • Client IP addresses are no longer stored by default. IPs are personal
    data; a new "Store Client IP Addresses" setting re-enables recording.
    Rate limiting is unaffected.

Added

  • "By Source" rollup view on the Violations tab: one row per blocked
    origin + directive with reports, affected pages, worst severity, and an
    in-policy status — plus a bulk Allow Selected Sources action that
    writes the checked origins straight into the policy.
  • Indexed blocked_origin column powering the rollup and status checks.
  • Policy-builder presets for reCAPTCHA, Jetpack/WordPress.com, UserWay,
    Userback, Cloudflare Insights, and jsDelivr.
  • JSON export now includes blocked_origin and emits numeric fields as
    numbers instead of strings.

Admin UI

  • Policy directive sources are now wrapping textareas, so long values are
    fully visible instead of truncating in a single-line field.
  • The Plugin Status endpoint URL wraps inside its box instead of overflowing.
  • The All Violations and By Source tables use the full admin width.