CSP Report-Only模式下form-action违规未发送至报告端点问题咨询
CSP Report-Only模式下表单违规无报告的原因分析
配置的响应头
content-security-policy-report-only default-src 'none'; base-uri 'self'; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; img-src https: data:; media-src https: data:; connect-src https:; font-src https:; frame-ancestors 'self'; frame-src https:; form-action 'self'; report-uri https://xxxx.ingest.de.sentry.io/api/xxxx/security/?sentry_key=xxxx; report-to csp-endpoint report-to {"group": "csp-endpoint", "max_age": 10886400, "endpoints": [{"url": "https://xxxx.ingest.de.sentry.io/api/xxxx/security/?sentry_key=xxxx"}], "include_subdomains": true} reporting-endpoints csp-endpoint="https://xxxx.ingest.de.sentry.io/api/xxxx/security/?sentry_key=xxxx"
控制台违规提示
[Report Only] Refused to send form data to 'https://domain.test.com/' because it violates the following Content Security Policy directive: "form-action 'self'".
问题诊断结论
你的判断完全正确。
在content-security-policy-report-only模式下,form-action 'self'的违规仅会在控制台给出提示,不会阻止表单提交跳转。页面会立即跳转到目标地址https://domain.test.com/,此时浏览器正在发起的CSP违规报告XHR请求会被页面跳转中断,无法完成发送。
而切换到content-security-policy强制执行模式时,浏览器会直接阻止表单跳转操作,页面不会刷新或跳转,因此违规报告的请求能顺利完成并发送到Sentry的报告端点。
内容的提问来源于stack exchange,提问作者SebCorbin
相关产品推荐
相关产品推荐

