Skip to content

fix: CSP blocking reCAPTCHA and Umami analytics#99

Merged
henfrydls merged 6 commits intomainfrom
fix/csp-analytics-recaptcha
Mar 20, 2026
Merged

fix: CSP blocking reCAPTCHA and Umami analytics#99
henfrydls merged 6 commits intomainfrom
fix/csp-analytics-recaptcha

Conversation

@henfrydls
Copy link
Copy Markdown
Owner

Both scripts were blocked by Content-Security-Policy. Adds required domains to script-src, connect-src, and frame-src.

- Disable SECURE_SSL_REDIRECT by default (configurable via env) to
  prevent redirect loops behind Nginx/ALB that handle SSL termination
- Change CSRF_COOKIE_SAMESITE from Strict to Lax to allow form
  submissions from external navigation
- Set CSRF_COOKIE_HTTPONLY to False to allow JS CSRF token reading
  for AJAX forms
- Derive ALLOWED_HOSTS from PRODUCTION_DOMAIN env var automatically
- Remove duplicate production_domain declaration
- Add google.com/recaptcha and gstatic.com/recaptcha to script-src
- Add frame-src for reCAPTCHA iframe
- Add analytics.henfrydls.com to script-src and connect-src
- Both were blocked:csp preventing reCAPTCHA and Umami from loading
@henfrydls henfrydls merged commit ad97753 into main Mar 20, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant