Skip to content

[HTTP/CDN] Set connect-src to HTTPS only when CDN is configured#179609

Merged
jloleysens merged 6 commits intoelastic:mainfrom
jloleysens:cdn/remove-connect-src
Apr 2, 2024
Merged

[HTTP/CDN] Set connect-src to HTTPS only when CDN is configured#179609
jloleysens merged 6 commits intoelastic:mainfrom
jloleysens:cdn/remove-connect-src

Conversation

@jloleysens
Copy link
Copy Markdown
Contributor

@jloleysens jloleysens commented Mar 28, 2024

Summary

Close #179061

@jloleysens jloleysens added Feature:http Team:Security Platform Security: Auth, Users, Roles, Spaces, Audit Logging, etc t// release_note:skip Skip the PR/issue when compiling release notes v8.14.0 labels Mar 28, 2024
@jloleysens
Copy link
Copy Markdown
Contributor Author

/ci

@jloleysens jloleysens added the ci:project-deploy-observability Create an Observability project label Mar 28, 2024
@jloleysens jloleysens marked this pull request as ready for review March 28, 2024 12:26
@jloleysens jloleysens requested a review from a team as a code owner March 28, 2024 12:26
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/kibana-security (Team:Security)

@jloleysens jloleysens changed the title [CDN] Remove connect-src from CSP when CDN is configured [HTTP/CDN] Set connect-src to HTTPS only when CDN is configured Mar 29, 2024
@kc13greiner kc13greiner self-requested a review April 1, 2024 18:34
Copy link
Copy Markdown
Contributor

@kc13greiner kc13greiner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@kibana-ci
Copy link
Copy Markdown

kibana-ci commented Apr 2, 2024

💚 Build Succeeded

Metrics [docs]

Canvas Sharable Runtime

The Canvas "shareable runtime" is an bundle produced to enable running Canvas workpads outside of Kibana. This bundle is included in third-party webpages that embed canvas and therefor should be as slim as possible.

id before after diff
module count - 5827 +5827
total size - 6.5MB +6.5MB

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@jloleysens jloleysens merged commit 849f8fb into elastic:main Apr 2, 2024
@kibanamachine kibanamachine added the backport:skip This PR does not require backporting label Apr 2, 2024
@jloleysens jloleysens deleted the cdn/remove-connect-src branch April 2, 2024 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:skip This PR does not require backporting ci:project-deploy-observability Create an Observability project Feature:http release_note:skip Skip the PR/issue when compiling release notes Team:Security Platform Security: Auth, Users, Roles, Spaces, Audit Logging, etc t// v8.14.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Serverless-observability-CDN-QA] Maps can't load external layers

6 participants