The Wayback Machine - https://web.archive.org/web/20200912112145/https://github.com/github/secure_headers/issues/269
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

report-uri is deprecated in favor of report-to #269

Open
connorshea opened this issue Jun 23, 2016 · 5 comments
Open

report-uri is deprecated in favor of report-to #269

connorshea opened this issue Jun 23, 2016 · 5 comments

Comments

@connorshea
Copy link
Contributor

@connorshea connorshea commented Jun 23, 2016

I don't know if the gem should be modified based on drafts of the spec, but I figured it was worth noting that the latest draft of the CSP standard replaces report-uri with report-to (Source).

Obviously report-uri shouldn't be removed, but report-to might want to be supported? I'm not particularly familiar with the W3C drafting process, so I'm not sure how much of this will be subject to significant change.

@oreoshake
Copy link
Member

@oreoshake oreoshake commented Jun 23, 2016

This library has an unofficial policy of "we'll wait until we see it IRL". If anyone has implemented report-to I think it's safe to make some changes. Just like #260, then it becomes an issue of UA sniffing to determine support.

Does anyone support report-to?

@connorshea
Copy link
Contributor Author

@connorshea connorshea commented Jun 23, 2016

Fair enough, to my knowledge this isn't in any browsers as of yet. Feel free to close this issue.

@oreoshake
Copy link
Member

@oreoshake oreoshake commented Jun 23, 2016

I'll leave it around until it disappears from the draft spec 😄

@oreoshake
Copy link
Member

@oreoshake oreoshake commented May 30, 2017

Blink has announced their intent to ship report-to support https://twitter.com/intenttoship/status/868025704432185344

@oreoshake oreoshake removed the draft-spec label Jun 21, 2017
@github github deleted a comment from Xosmond Jul 21, 2017
@github github deleted a comment from jacobbednarz Jul 21, 2017
@github github deleted a comment from Xosmond Jul 21, 2017
@github github deleted a comment from jacobbednarz Jul 21, 2017
@github github deleted a comment from jacobbednarz Jul 21, 2017
@github github deleted a comment from connorshea Jul 21, 2017
@github github deleted a comment from connorshea Jul 21, 2017
@scottschup
Copy link

@scottschup scottschup commented Mar 12, 2020

report-to is now supported in Chrome and Edge and several mobile platforms. Might be time to start thinking about reviving this task.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-to#Browser_compatibility

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
3 participants
You can’t perform that action at this time.