Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ECP-9530] Update CSP domain allow list #2785

Merged
merged 6 commits into from
Oct 30, 2024
Merged

[ECP-9530] Update CSP domain allow list #2785

merged 6 commits into from
Oct 30, 2024

Conversation

candemiralp
Copy link
Member

@candemiralp candemiralp commented Oct 28, 2024

Description

Due to the latest changes on Adobe's CSP rules restrictions according to PCI 4.0 regulations, Following domains have been added to CSP rules allow list.

  • payments-amazon.com
  • payments.amazon.de
  • payments-eu.amazon.com
  • media-amazon.com
  • paypal.com
  • paypalobjects.com
  • ratepay.com
  • google.com

Note
This is an iterative process and the domains will be added once discovered. Please feel free to create a follow-up PR or open a Github Issue for missing strict CSP rules.

Copy link

sonarcloud bot commented Oct 30, 2024

@candemiralp candemiralp merged commit eb96589 into main Oct 30, 2024
15 of 16 checks passed
@candemiralp candemiralp deleted the ECP-9530 branch October 30, 2024 15:47
@github-actions github-actions bot mentioned this pull request Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants