-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove blob: from our worker-src CSP directive #140388
Conversation
💔 Build FailedFailed CI Steps
Test Failures
Metrics [docs]
HistoryTo update your PR or re-run it, just comment with: |
It appears that our code editor ( |
Ugh, thanks for figuring this out! Here are the relevant log lines, just for the record:
|
Ah, so it seems that |
Summary
Removes
blob:
from ourworker-src
CSP directive. This was included in our original CSP definition via #29545, and it appears it was only required for use by our geo features (e.g. Maps).A lot has changed since then, so I'm opening this PR to see if it is viable to remove this directive from our CSP.
Findings
worker-src blob:
cannot be removed from our CSP at this time because it is required by theace
editor. We can technically runace
without web worker support, but I suspect this would come with a performance penalty. I am not comfortable making this change at this time given the widespread usage within Kibana.