Skip to content

#16 add the option to make RUMvision load with CSP compliance#17

Open
larsmbm wants to merge 1 commit into
elgentos:mainfrom
larsmbm:#16-Make-module-work-with-Hyva-CSP
Open

#16 add the option to make RUMvision load with CSP compliance#17
larsmbm wants to merge 1 commit into
elgentos:mainfrom
larsmbm:#16-Make-module-work-with-Hyva-CSP

Conversation

@larsmbm
Copy link
Copy Markdown

@larsmbm larsmbm commented Nov 20, 2025

No description provided.

@peterjaap
Copy link
Copy Markdown
Contributor

I'm not seeing an option here? Just the XML and phtml, but no config, or ifconfig?

@larsmbm
Copy link
Copy Markdown
Author

larsmbm commented Nov 21, 2025

I'm not seeing an option here? Just the XML and phtml, but no config, or ifconfig?

The commit message wasn’t accurate. I pushed this a bit too hastily.

Could you let me know how you’d prefer the changes to this module to be handled so we can make it fully CSP compliant? We need to add a nonce for the inline script and include CloudFront in the allowlist.

One option is to use Hyvä CSP, but that only works on Hyvä versions that support the CSP viewmodel. Also, for full CSP compliance we can’t keep using eval(), so that part still needs to be updated as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants