Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion cms/settings/base.py
Original file line number Diff line number Diff line change
Expand Up @@ -1229,7 +1229,14 @@ def _iam_database_config(host: str) -> dj_database_url.DBConfig:
"frame-src": [CSP.SELF, *IFRAME_VISUALISATION_CSP_SOURCES, *VIDEO_EMBED_CSP_SOURCES],
# UNSAFE_INLINE is required by mathjax
"style-src": [CSP.SELF, *static_sources, CSP.UNSAFE_INLINE, "*.hotjar.com"],
"img-src": [CSP.SELF, ONS_CDN_URL, "www.googletagmanager.com", "*.google-analytics.com", "*.hotjar.com"],
"img-src": [
CSP.SELF,
ONS_CDN_URL,
"www.googletagmanager.com",
"*.google-analytics.com",
"*.hotjar.com",
"https://bossanova.uk/jspreadsheet/logo.png",
],
# UNSAFE_INLINE is required by hotjar
"script-src": [CSP.SELF, *static_sources, "*.hotjar.com", "www.googletagmanager.com", CSP.UNSAFE_INLINE],
"font-src": [CSP.SELF, *static_sources, "*.hotjar.com"],
Expand Down
12 changes: 12 additions & 0 deletions cms/settings/tests/test_settings.py
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,18 @@ def test_hotjar_csp(self):
self.assertIn("*.hotjar.com", self._get_csp_expressions(csp, "style-src"))
self.assertIn(CSP.UNSAFE_INLINE, self._get_csp_expressions(csp, "style-src"))

def test_jspreadsheet_logo_csp(self):
for url in self.urls:
with self.subTest(url):
response = self.client.get(url)

csp = self._parse_csp(response.headers["Content-Security-Policy"])

self.assertIn(
"https://bossanova.uk/jspreadsheet/logo.png",
self._get_csp_expressions(csp, "img-src"),
)

def test_mathjax_csp(self):
for url in self.urls:
with self.subTest(url):
Expand Down
Loading