Closed Bug 746203 Opened 13 years ago Closed 13 years ago

Gravatar images violate CSP

Categories

(Participation Infrastructure :: Phonebook, defect)

defect
Not set
normal

Tracking

(Not tracked)

VERIFIED FIXED
2012-04-25

People

(Reporter: jsocol, Assigned: jsocol)

Details

Images from gravatar servers violate the current CSP. We need to whitelist gravatar in the img-src directive. c.f. the CSP_IMG_SRC setting.
Assignee: nobody → james
Whiteboard: [rel:25/04/2012]
Commits pushed to master at https://github.com/mozilla/mozillians https://github.com/mozilla/mozillians/commit/5cbd32c7b850f2188bf5fc29641cf96ac25a6b9c [Fix bug 746203] Add gravatar to img-src whitelist. https://github.com/mozilla/mozillians/commit/816c82aae357a93e297bf3e5b5aaab4f688db5fc Merge pull request #221 from jsocol/img-src [Fix bug 746203] Add gravatar to img-src whitelist.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Status: REOPENED → RESOLVED
Closed: 13 years ago13 years ago
Resolution: --- → FIXED
Target Milestone: --- → 2012-04-25
Whiteboard: [rel:25/04/2012]
Bumping to verified - no more CSP violations for Gravatar images are being received. Thx James.
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.