Skip to content

Commit

Permalink
Magento csp policies (#12)
Browse files Browse the repository at this point in the history
  • Loading branch information
gromovdmi authored Oct 6, 2022
1 parent 9e544eb commit 67ab567
Show file tree
Hide file tree
Showing 2 changed files with 36 additions and 0 deletions.
9 changes: 9 additions & 0 deletions etc/config.xml
Original file line number Diff line number Diff line change
Expand Up @@ -17,5 +17,14 @@
<skuAttr>sku</skuAttr>
</general>
</metrika>
<csp>
<policies>
<storefront>
<frame-ancestors>
<inline>0</inline>
</frame-ancestors>
</storefront>
</policies>
</csp>
</default>
</config>
27 changes: 27 additions & 0 deletions etc/csp_whitelist.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
<?xml version="1.0"?>
<csp_whitelist xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="urn:magento:module:Magento_Csp:etc/csp_whitelist.xsd">
<policies>
<policy id="script-src">
<values>
<value id="yandexMetrikaScripts" type="host">mc.yandex.ru</value>
<value id="yastatic" type="host">yastatic.net</value>
</values>
</policy>
<policy id="connect-src">
<values>
<value id="yandexMetrikaConnect" type="host">mc.yandex.ru</value>
</values>
</policy>
<policy id="img-src">
<values>
<value id="mcYandex" type="host">mc.yandex.ru</value>
</values>
</policy>
<policy id="frame-ancestors">
<values>
<value id="webvisor" type="host">webvisor.com</value>
<value id="metrikaYandexRu" type="host">metrika.yandex.ru</value>
</values>
</policy>
</policies>
</csp_whitelist>

0 comments on commit 67ab567

Please sign in to comment.