Skip to content

Commit f1801bd

Browse files
authored
Merge branch 'main' into update-link-script
2 parents 6ac9bc8 + 7f577d0 commit f1801bd

File tree

2 files changed

+3
-4
lines changed

2 files changed

+3
-4
lines changed

customHttp.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,5 +13,5 @@ customHeaders:
1313
- key: 'X-Content-Type-Options'
1414
value: 'nosniff'
1515
- key: 'Content-Security-Policy'
16-
value: "upgrade-insecure-requests; default-src 'none'; prefetch-src 'self'; style-src 'self' 'unsafe-inline' *.shortbread.aws.dev; font-src 'self'; frame-src 'self' https://www.youtube-nocookie.com https://aws.demdex.net https://dpm.demdex.net; connect-src 'self' *.shortbread.aws.dev https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://d2c.aws.amazon.com https://vs.aws.amazon.com https://*.algolia.net https://*.algolianet.com *.amazonaws.com https://aws.amazon.com/ https://d2c-alpha.dse.marketing.aws.a2z.com https://aws-mktg-csds-alpha.integ.amazon.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; img-src 'self' https://img.shields.io https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; media-src 'self'; script-src 'self' *.shortbread.aws.dev https://a0.awsstatic.com/ https://aa0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://d2c.aws.amazon.com/;"
16+
value: "upgrade-insecure-requests; default-src 'none'; style-src 'self' 'unsafe-inline' *.shortbread.aws.dev; font-src 'self'; frame-src 'self' https://www.youtube-nocookie.com https://aws.demdex.net https://dpm.demdex.net; connect-src 'self' *.shortbread.aws.dev https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://d2c.aws.amazon.com https://vs.aws.amazon.com https://*.algolia.net https://*.algolianet.com *.amazonaws.com https://aws.amazon.com/ https://d2c-alpha.dse.marketing.aws.a2z.com https://aws-mktg-csds-alpha.integ.amazon.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; img-src 'self' https://img.shields.io https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; media-src 'self'; script-src 'self' *.shortbread.aws.dev https://a0.awsstatic.com/ https://aa0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://d2c.aws.amazon.com/;"
1717
# CSP also set in _document.tsx meta tag

src/pages/_document.tsx

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,8 @@ const ANALYTICS_CSP = {
4141
'https://aa0.awsstatic.com/',
4242
'https://alpha.d2c.marketing.aws.dev/',
4343
'https://aws-mktg-csds-alpha.integ.amazon.com/',
44-
'https://d2c-alpha.dse.marketing.aws.a2z.com'
44+
'https://d2c-alpha.dse.marketing.aws.a2z.com',
45+
'https://vs-alpha.aws.amazon.com'
4546
],
4647
img: ['https://aa0.awsstatic.com/', 'https://alpha.d2c.marketing.aws.dev/'],
4748
script: [
@@ -61,7 +62,6 @@ const getCspContent = (context) => {
6162
if (process.env.BUILD_ENV !== 'production') {
6263
return `upgrade-insecure-requests;
6364
default-src 'none';
64-
prefetch-src 'self';
6565
style-src 'self' 'unsafe-inline' ${ANALYTICS_CSP.all.style.join(' ')};
6666
font-src 'self' data:;
6767
frame-src 'self' https://www.youtube-nocookie.com ${ANALYTICS_CSP.all.frame.join(
@@ -85,7 +85,6 @@ const getCspContent = (context) => {
8585
// Have to keep track of CSP inside customHttp.yml as well
8686
return `upgrade-insecure-requests;
8787
default-src 'none';
88-
prefetch-src 'self';
8988
style-src 'self' 'unsafe-inline' ${ANALYTICS_CSP.all.style.join(' ')};
9089
font-src 'self';
9190
frame-src 'self' https://www.youtube-nocookie.com ${ANALYTICS_CSP.all.frame.join(

0 commit comments

Comments
 (0)