koehnlein, (edited )
@koehnlein@mastodon.social avatar

I had trouble with Content-Security-Policy reporting on a password protected staging environment in combination with Firefox. I found a nice solution and blogged about it:

https://www.koehnlein.eu/en/blog/2024/csp-reporting-basic-auth/

#CSP #Apache #Firefox

danielsiepmann,

@koehnlein Thanks for sharing :) I guess Firefox added a layer of security. It no longer passes basic auth in URLs.

It would ask you whether it was expected in order to be confirmed by a user. But that doesn't we to work for those inner requests.

Just as an possible explanation why your, and mine, favourite browser doesn't "support" that.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • firefox
  • InstantRegret
  • ngwrru68w68
  • everett
  • mdbf
  • modclub
  • rosin
  • khanakhh
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Youngstown
  • GTA5RPClips
  • slotface
  • kavyap
  • JUstTest
  • ethstaker
  • osvaldo12
  • normalnudes
  • tacticalgear
  • cisconetworking
  • cubers
  • Durango
  • Leos
  • anitta
  • tester
  • megavids
  • provamag3
  • lostlight
  • All magazines