This repository was archived by the owner on Sep 9, 2026. It is now read-only.
Ship a CSP, and make sure Jekyll actually copies it - #18
Merged
Merged
Conversation
gsamanager.org was the only site in the estate serving no Content-Security-Policy at all -- which is why its analytics worked: nothing restricted them. Every source in the policy is something the site loads, read off the built output rather than assumed: Turnstile and self-hosted Plausible for scripts, the Google Fonts stylesheet for styles, fonts.gstatic.com for faces, Plausible's beacon and the mailer for connections, and Turnstile again under frame-src because it renders itself into an iframe. One inline script drives the contact form, hence 'unsafe-inline' on script-src. No external images anywhere in the repo, so img-src stays 'self' data:. The part that would have failed silently: Jekyll drops underscore-prefixed files from _site, so `_headers` had to be named in `include:` beside `.well-known`. Without that line the file sits in the repo looking correct and never reaches the build, and the site keeps serving no policy. Delete the include line and you delete the CSP. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0119vXMJC7FKdDTYJkLVLusg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
gsamanager.orgwas the only site in the estate serving no Content-Security-Policy — found while sweeping all 30 sites for CSPs that silently block Plausible. Its analytics worked precisely because nothing restricted them.The policy
Every source is something the site actually loads, read off the built output rather than assumed:
script-src'unsafe-inline'for the one inline script driving the contact form.style-srcfont-srcfonts.gstatic.com, plusdata:.connect-srcmailer.thompsonblack.us, which takes the contact POST.frame-srcimg-src'self' data:— a full-repo scan found no external image loads.The part that would have failed silently
Jekyll drops underscore-prefixed files from
_site. A_headersfile sitting at the repo root looks correct, never reaches the build, and the site keeps serving no policy. It has to be named ininclude:beside.well-known:Delete that line and you delete the CSP, with nothing to indicate it. Verified with a local
bundle exec jekyll build—_site/_headersis present.Worth checking after merge
default-src 'none'is unforgiving. Confirm the contact form still submits and Turnstile still renders — those are the two things this could break.🤖 Generated with Claude Code
https://claude.ai/code/session_0119vXMJC7FKdDTYJkLVLusg