Skip to content

Omit CSP report-uri when CSP_REPORT_URI is unset - #3178

Merged
JacobCoffee merged 1 commit into
mainfrom
fix/csp-report-uri-none
Oct 8, 2026
Merged

JacobCoffee merged 1 commit into
mainfrom
fix/csp-report-uri-none

Conversation

@JacobCoffee

Copy link
Copy Markdown
Member

With CSP_REPORT_URI unset (local dev), the Report-Only header went out as the literal report-uri None, so browsers POSTed every violation report to <current page>/None and got 404s.

django-csp 4.0 already leaves out directives whose value is None, but base.py wrapped the setting in a list ([_CSP_REPORT_URI]), so it stringified None instead. This passes the bare value, which matches the existing comment.

Checked by building the policy with csp.utils.build_policy(report_only=True):

CSP_REPORT_URI before after
unset report-uri None omitted
https://example.com/csp report-uri https://example.com/csp same

Prod sets the variable, so its header is unchanged. pydotorg.tests.test_middleware passes.

django-csp skips directives whose value is None, but wrapping the
setting in a list sent the literal 'report-uri None' locally, so
browsers POSTed violation reports to <page>/None.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 05:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T05:02:11.605658Z e609c39 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@JacobCoffee
JacobCoffee merged commit df3d2b8 into main Oct 8, 2026
12 checks passed
@JacobCoffee
JacobCoffee deleted the fix/csp-report-uri-none branch October 8, 2026 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants