Commit aaee91a
Fix reporting when only the report-only CSP header is present
This was a bit confusing at first, but the report-only only
had an effect if it was used in conjunction with the regular
CSP header. This is incorrect, as the report-only header
can be present on its own.
Additionally, there was double-logic for parsing the CSP list
values, since we can only concatenate CSP lists if we have
an initial value, which requires a concrete policy value.
Therefore, abstract that way by looping over both headers and
handling the case where initially it is `None` and, if the
CSP header is not present, still `None` when we parse
the `report-only` header.
Additionally, update two WPT tests. One was expecting the image
to load, yet was showing the fail image. The other one is
currently still failing for Servo, but crashes the test runner.
Now it no longer times out, but has the wrong value for
number of reports.
Part of #4577
Signed-off-by: Tim van der Lippe <tvanderlippe@gmail.com>1 parent 1570919 commit aaee91a
1 file changed
Lines changed: 3 additions & 3 deletions
File tree
- content-security-policy/reporting-api
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
0 commit comments