Skip to content

Restore tracker and shared capture scripts blocked by root CSP #3

Description

@sarthakagrawal927

Verified defect

Chrome Network records CSP blocks for the existing App Health tracker, newsletter capture and shared AI/feedback footer scripts. The document response policy matches next.config.ts securityHeaders. Local project-strip loads successfully. Newsletter has no shadow root and feedback/extension are absent.

Proposed bounded repair

Add exactly https://sassmaker.com and https://health.sassmaker.com to the existing script-src allowlist in next.config.ts. Preserve all other directives and headers. No credentials, dependencies, provider bindings, or wildcard hosts. These are the first-party producers already referenced by the product HTML.

Release gate

Owner approval required by Fleet production-config boundary. After approval use a clean managed writer; validate policy regression and normal build/CI; release exact main through existing guarded workflow; verify browser document CSP and loaded tracker/capture/feedback, including responsive dialog. Do not submit synthetic feedback or joins. Rollback is removal of the two explicit hosts.

Caveat

Source/header verification alone is insufficient: the first observation used HTTP headers lacking this CSP, whereas fresh Chrome Network exposes the effective response policy and blocked script IDs. Browser runtime is the acceptance source.


Recreated from original issue #83 (repo recreated 2026-10-04 to purge leaked personal data and a secret from git history).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions