We're calling on all EU-based Mozillians with iOS or iPadOS devices to help us monitor Apple’s new browser choice screens. Join the effort to hold Big Tech to account!

Rechercher dans l’assistance

Évitez les escroqueries à l’assistance. Nous ne vous demanderons jamais d’appeler ou d’envoyer un SMS à un numéro de téléphone ou de partager des informations personnelles. Veuillez signaler toute activité suspecte en utilisant l’option « Signaler un abus ».

En savoir plus

Couldn’t process unknown directive ‘report-to’

  • 1 réponse
  • 0 a ce problème
  • 33 vues
  • Dernière réponse par Standard8

more options

Hello there, I'm getting following warnings when I set report-to directive.

Content-Security-Policy: Couldn’t process unknown directive ‘report-to’ Content-Security-Policy: This site (http://puvipavan.local) has a Report-Only policy without a report URI. CSP will not block and cannot report violations of this policy.

These are the passed headers:

Content-Security-Policy-Report-Only: default-src https:; report-to csp-endpoint; Report-To: { "group": "csp-endpoint", "max_age": 5000, "endpoints": [ { "url": "https://example.com/csp-reports" } ] }

Am I missing something? I'm using the latest version of Firefox as of July-31-2023(115.0.3 (64-bit))

Hello there, I'm getting following warnings when I set report-to directive. Content-Security-Policy: Couldn’t process unknown directive ‘report-to’ Content-Security-Policy: This site (http://puvipavan.local) has a Report-Only policy without a report URI. CSP will not block and cannot report violations of this policy. These are the passed headers: Content-Security-Policy-Report-Only: default-src https:; report-to csp-endpoint; Report-To: { "group": "csp-endpoint", "max_age": 5000, "endpoints": [ { "url": "https://example.com/csp-reports" } ] } Am I missing something? I'm using the latest version of Firefox as of July-31-2023(115.0.3 (64-bit))

Toutes les réponses (1)

more options

Hi,

According to this table to this table, Firefox does not currently support report-to.

You can probably use the report-uri directive instead for the time being.