{"id":302697,"date":"2020-04-28T21:00:22","date_gmt":"2020-04-28T21:00:22","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=302697"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=302697","title":{"rendered":"Content Security Policy \u0432 Magento 2"},"content":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/498796\/\">\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442!<\/p>\n<p>  \u041d\u0430\u0432\u0435\u0440\u043d\u044f\u043a\u0430 \u0432\u044b, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0432 Magento 2.3.5 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u0432 \u0441\u0432\u043e\u0438\u0445 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043d\u044b\u0445 \u043a\u043e\u043d\u0441\u043e\u043b\u044f\u0445 \u0447\u0442\u043e-\u0442\u043e \u0432\u0440\u043e\u0434\u0435<\/p>\n<p>  <i>[Report Only] Refused to load the script &#8216;***&#8217; because it violates the following Content Security Policy directive: \u00abscript-src *\u00bb. Note that &#8216;script-src-elem&#8217; was not explicitly set, so &#8216;script-src&#8217; is used as a fallback.<\/i><\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/nk\/g0\/vn\/nkg0vngypittau4bisxqhqumlx0.png\"><\/p>\n<p>  \u041e \u0442\u043e\u043c, \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0442\u044c, \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043f\u043e\u0434 \u043a\u0430\u0442\u043e\u043c<br \/>  <a name=\"habracut\"><\/a>  <\/p>\n<h3>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435<\/h3>\n<p>  \u041d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u0435\u0440\u0441\u0438\u0438 2.3.5 \u0432 Magento \u043f\u043e\u044f\u0432\u0438\u043b\u0441\u044f \u043c\u043e\u0434\u0443\u043b\u044c \u043f\u043e\u0434 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435\u043c Magento_CSP. \u041e\u043d \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 Content Security Policy, \u0438, \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a <b>Content-Security-Policy<\/b>, \u0430 \u0442\u043e\u0447\u043d\u0435\u0435, \u043f\u043e\u043a\u0430 <b>Content-Security-Policy-Report-Only<\/b>. \u041a\u0430\u043a \u0432\u0441\u0435\u0433\u0434\u0430 \u0432\u043e\u0432\u0440\u0435\u043c\u044f \u0438 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u043d\u043e \u043e\u0436\u0438\u0434\u0430\u0435\u043c\u043e, \u043f\u0440\u0438 \u043f\u043e\u0434\u043d\u044f\u0442\u0438\u0438 \u00ab\u0444\u0438\u043a\u0441\u00bb \u0432\u0435\u0440\u0441\u0438\u0438 \ud83d\ude42<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/hi\/qq\/ni\/hiqqninnzowqvciau5jbdqsv0wo.jpeg\"><\/p>\n<p>  \u041e \u0442\u043e\u043c, \u0447\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Content Security Policy \u0438 \u0441 \u0447\u0435\u043c \u0435\u0433\u043e \u0435\u0434\u044f\u0442, <a href=\"https:\/\/habr.com\/ru\/company\/nix\/blog\/271575\/\">\u0443\u0436\u0435 \u043f\u0438\u0441\u0430\u043b\u0438 \u043d\u0430 \u0425\u0430\u0431\u0440\u0435<\/a>.<\/p>\n<p>  \u0412\u044b\u0431\u043e\u0440 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430 <b>Content-Security-Policy<\/b> \u0438\u043b\u0438 <b>Content-Security-Policy-Report-Only<\/b> \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0442 \u043a\u043e\u043d\u0444\u0438\u0433 \u0444\u0430\u0439\u043b\u0430 <i>vendor\/magento\/module-csp\/etc\/config.xml<\/i> \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u0434\u043b\u044f \u0444\u0440\u043e\u043d\u0442 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u0434\u043b\u044f \u0430\u0434\u043c\u0438\u043d \u0447\u0430\u0441\u0442\u0438.<\/p>\n<pre><code class=\"xml\">&lt;config xmlns:xsi=&quot;http:\/\/www.w3.org\/2001\/XMLSchema-instance&quot; xsi:noNamespaceSchemaLocation=&quot;urn:magento:module:Magento_Store:etc\/config.xsd&quot;&gt;     &lt;default&gt;         &lt;csp&gt;             &lt;mode&gt;                 &lt;storefront&gt;                     &lt;report_only&gt;1&lt;\/report_only&gt;                 &lt;\/storefront&gt;                 &lt;admin&gt;                     &lt;report_only&gt;1&lt;\/report_only&gt;                 &lt;\/admin&gt;             &lt;\/mode&gt;         &lt;\/csp&gt;     &lt;\/default&gt; &lt;\/config&gt; <\/code><\/pre>\n<p>  \u0422\u0430\u043c \u0436\u0435 \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u0435 \u00abreport_uri\u00bb \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u0431\u044b \u0437\u0430\u0434\u0430\u0442\u044c \u0443\u0440\u043b \u0434\u043b\u044f \u0440\u0435\u043f\u043e\u0440\u0442\u0430, \u043d\u043e \u0442.\u043a. \u0435\u0433\u043e \u0442\u0430\u043c \u043d\u0435\u0442, \u0442\u043e \u0445\u0440\u043e\u043c \u043d\u0435\u0449\u0430\u0434\u043d\u043e \u043a\u0440\u0430\u0441\u043d\u0438\u0442 \u043a\u043e\u043d\u0441\u043e\u043b\u044c \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0435\u043c \u043e\u0431 \u0435\u0433\u043e \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0438.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/yv\/uu\/sy\/yvuusym94rwuaghp82ngrbieygq.png\"><\/p>\n<div class=\"spoiler\" role=\"button\" tabindex=\"0\">                         <b class=\"spoiler_title\">\u041f\u0440\u0438\u043c\u0435\u0440\u043d\u044b\u0439 \u0442\u0435\u043a\u0441\u0442 \u043e\u0448\u0438\u0431\u043a\u0438<\/b>                         <\/p>\n<div class=\"spoiler_text\">The Content Security Policy &#8216;font-src &#8216;self&#8217; &#8216;unsafe-inline&#8217;; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com &#8216;self&#8217; &#8216;unsafe-inline&#8217;; frame-ancestors &#8216;self&#8217; &#8216;unsafe-inline&#8217;; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com <a href=\"http:\/\/www.paypal.com\" rel=\"nofollow\">www.paypal.com<\/a> <a href=\"http:\/\/www.sandbox.paypal.com\" rel=\"nofollow\">www.sandbox.paypal.com<\/a> &#8216;self&#8217; &#8216;unsafe-inline&#8217;; img-src widgets.magentocommerce.com <a href=\"http:\/\/www.googleadservices.com\" rel=\"nofollow\">www.googleadservices.com<\/a> <a href=\"http:\/\/www.google-analytics.com\" rel=\"nofollow\">www.google-analytics.com<\/a> t.paypal.com <a href=\"http:\/\/www.paypal.com\" rel=\"nofollow\">www.paypal.com<\/a> <a href=\"http:\/\/www.paypalobjects.com\" rel=\"nofollow\">www.paypalobjects.com<\/a> fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com &#8216;self&#8217; &#8216;unsafe-inline&#8217;; script-src assets.adobedtm.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com js.authorize.net jstest.authorize.net <a href=\"http:\/\/www.googleadservices.com\" rel=\"nofollow\">www.googleadservices.com<\/a> <a href=\"http:\/\/www.google-analytics.com\" rel=\"nofollow\">www.google-analytics.com<\/a> <a href=\"http:\/\/www.paypal.com\" rel=\"nofollow\">www.paypal.com<\/a> <a href=\"http:\/\/www.sandbox.paypal.com\" rel=\"nofollow\">www.sandbox.paypal.com<\/a> <a href=\"http:\/\/www.paypalobjects.com\" rel=\"nofollow\">www.paypalobjects.com<\/a> t.paypal.com js.braintreegateway.com s.ytimg.com video.google.com vimeo.com <a href=\"http:\/\/www.vimeo.com\" rel=\"nofollow\">www.vimeo.com<\/a> cdn-scripts.signifyd.com <a href=\"http:\/\/www.youtube.com\" rel=\"nofollow\">www.youtube.com<\/a> &#8216;self&#8217; &#8216;unsafe-inline&#8217; &#8216;unsafe-eval&#8217;; style-src getfirebug.com &#8216;self&#8217; &#8216;unsafe-inline&#8217;; object-src &#8216;self&#8217; &#8216;unsafe-inline&#8217;; media-src &#8216;self&#8217; &#8216;unsafe-inline&#8217;; manifest-src &#8216;self&#8217; &#8216;unsafe-inline&#8217;; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com &#8216;self&#8217; &#8216;unsafe-inline&#8217;; child-src &#8216;self&#8217; &#8216;unsafe-inline&#8217;; default-src &#8216;self&#8217; &#8216;unsafe-inline&#8217; &#8216;unsafe-eval&#8217;; base-uri &#8216;self&#8217; &#8216;unsafe-inline&#8217;;&#8217; was delivered in report-only mode, but does not specify a &#8216;report-uri&#8217;; the policy will have no effect. Please either add a &#8216;report-uri&#8217; directive, or deliver the policy via the &#8216;Content-Security-Policy&#8217; header.  <\/div>\n<\/p><\/div>\n<p>  <\/p>\n<h3>\u041a\u0430\u043a \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u0443\u0440\u043b \u0432 \u043f\u043e\u043b\u0438\u0441\u0438?<\/h3>\n<p>  \u0421\u043e\u0437\u0434\u0430\u0435\u043c \u0444\u0430\u0439\u043b\u0438\u043a \u0432 \u043a\u043e\u0440\u043d\u0435 \u043f\u0430\u043f\u043a\u0438 \/etc\/ \u043c\u043e\u0434\u0443\u043b\u044f \u0441 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435\u043c <b>csp_whitelist.xml<\/b> \u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c<\/p>\n<pre><code class=\"xml\">&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt; &lt;csp_whitelist xmlns:xsi=&quot;http:\/\/www.w3.org\/2001\/XMLSchema-instance&quot;                xsi:noNamespaceSchemaLocation=&quot;urn:magento:module:Magento_Csp:etc\/csp_whitelist.xsd&quot;&gt;     &lt;policies&gt;         &lt;policy id=&quot;POLICY_ID&quot;&gt;             &lt;values&gt;                 &lt;value id=&quot;VALUE_ID&quot; type=&quot;TYPE&quot; algorithm=&quot;ALGORITHM&quot;&gt;SOME DOMAIN&lt;\/value&gt;             &lt;\/values&gt;         &lt;\/policy&gt;     &lt;\/policies&gt; &lt;\/csp_whitelist&gt; <\/code><\/pre>\n<p>  \u0433\u0434\u0435 POLICY_ID \u043e\u0434\u0438\u043d \u0438\u0437:<\/p>\n<ul>\n<li>default-src<\/li>\n<li>script-src<\/li>\n<li>object-src<\/li>\n<li>style-src<\/li>\n<li>img-src<\/li>\n<li>media-src<\/li>\n<li>frame-src<\/li>\n<li>font-src<\/li>\n<li>connect-src<\/li>\n<\/ul>\n<p>  VALUE_ID \u2014 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0435 \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u043e\u0435 \u0438\u043c\u044f<br \/>  TYPE \u2014 \u0442\u0438\u043f, \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0442\u044c \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f <b>domain<\/b> \u0438\u043b\u0438 <b>hash<\/b><br \/>  ALGORITHM \u2014 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0445\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f (\u043f\u0440\u0438 TYPE=hash), \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 <b>sha256<\/b><\/p>\n<p>  \u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043f\u0440\u0438\u043c\u0435\u0440\u044b \u0438\u0437 <a href=\"http:\/\/vendor\/magento\/magento2-base\/dev\/tests\/integration\/_files\/Magento\/TestModuleCspConfig\/etc\/csp_whitelist.xml\" rel=\"nofollow\">\u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0442\u0435\u0441\u0442\u0430 \u0441\u0430\u043c\u043e\u0439 Magento<\/a>:<\/p>\n<pre><code class=\"xml\">&lt;?xml version=&quot;1.0&quot;?&gt; &lt;!-- \/**  * Copyright  Magento, Inc. All rights reserved.  * See COPYING.txt for license details.  *\/ --&gt; &lt;csp_whitelist xmlns:xsi=&quot;http:\/\/www.w3.org\/2001\/XMLSchema-instance&quot; xsi:noNamespaceSchemaLocation=&quot;urn:magento:module:Magento_Csp\/etc\/csp_whitelist.xsd&quot;&gt;     &lt;policies&gt;         &lt;policy id=&quot;object-src&quot;&gt;             &lt;values&gt;                 &lt;value id=&quot;mage-base&quot; type=&quot;host&quot;&gt;https:\/\/magento.com&lt;\/value&gt;                 &lt;value id=&quot;hash&quot; type=&quot;hash&quot; algorithm=&quot;sha256&quot;&gt;B2yPHKaXnvFWtRChIbabYmUBFZdVfKKXHbWtWidDVF8=&lt;\/value&gt;                 &lt;value id=&quot;hash2&quot; type=&quot;hash&quot; algorithm=&quot;sha256&quot;&gt;B3yPHKaXnvFWtRChIbabYmUBFZdVfKKXHbWtWidDVF8=&lt;\/value&gt;             &lt;\/values&gt;         &lt;\/policy&gt;         &lt;policy id=&quot;media-src&quot;&gt;             &lt;values&gt;                 &lt;value id=&quot;mage-base&quot; type=&quot;host&quot;&gt;https:\/\/magento.com&lt;\/value&gt;                 &lt;value id=&quot;devdocs-base&quot; type=&quot;host&quot;&gt;https:\/\/devdocs.magento.com&lt;\/value&gt;             &lt;\/values&gt;         &lt;\/policy&gt;     &lt;\/policies&gt; &lt;\/csp_whitelist&gt; <\/code><\/pre>\n<\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/post\/498796\/\"> https:\/\/habr.com\/ru\/post\/498796\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/498796\/\">\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442!<\/p>\n<p>  \u041d\u0430\u0432\u0435\u0440\u043d\u044f\u043a\u0430 \u0432\u044b, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0432 Magento 2.3.5 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438 \u0432 \u0441\u0432\u043e\u0438\u0445 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043d\u044b\u0445 \u043a\u043e\u043d\u0441\u043e\u043b\u044f\u0445 \u0447\u0442\u043e-\u0442\u043e \u0432\u0440\u043e\u0434\u0435<\/p>\n<p>  <i>[Report Only] Refused to load the script &#8216;***&#8217; because it violates the following Content Security Policy directive: \u00abscript-src *\u00bb. Note that &#8216;script-src-elem&#8217; was not explicitly set, so &#8216;script-src&#8217; is used as a fallback.<\/i><\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/nk\/g0\/vn\/nkg0vngypittau4bisxqhqumlx0.png\"><\/p>\n<p>  \u041e \u0442\u043e\u043c, \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0442\u044c, \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043f\u043e\u0434 \u043a\u0430\u0442\u043e\u043c  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-302697","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/302697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=302697"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/302697\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=302697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=302697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=302697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}