Enable csp report_only mode to not block inline script in the sequra … #28
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What is the goal?
Have the checkout working agin with the new Content Secutiry Policies at MAgento 2.4.7
References
How is it being implemented?
We have enabled the report_only mode for our plugin
Our checkout form needs an inline script that changes and is generated outside Magento so that we can't generate a hash to add it to the csp_whitelist or use a nonce provider.
Opportunistic refactorings
Version bump
Caveats
Does it affect (changes or update) any sensitive data?
How is it tested?
Manual tests