4 ms·
Speaking about Safari bugs I got concerned with lately: you cannot use Content-Security-Policy if you use web sockets with Safari: https://bugs.webkit.org/show_
by chrizel 5y ago
Speaking about Safari bugs I got concerned with lately: you cannot use Content-Security-Policy if you use web sockets with Safari: https://bugs.webkit.org/show_bug.cgi?id=201591 https://bugs.webkit.org/show_bug.cgi?id=201591
I don’t understand why this doesn’t get more attention.
It is just infuriating if you can’t use a security feature, just because some browser doesn’t follow the specs correctly. Oh well, time repeats itself just like with IE.
And just for a moment we thought we are behind all of this.
- dwaite 5y agoyou cannot use connect-src self. You can use CSP just fine if you are more explicit.
- chrizel 5y agoChecked it again. You are right about this - if I define it as 'connect-src 'self' wss://<domain>' it works - not without the 'wss://', which I tried last week. Thanks for the nudge. At least we have a workaround.
- merrywhether 5y agoProtocol is part of a FQDN, so this isn’t entirely surprising.