ENG-2404: Update CSP headers to include docs pages#7235
Merged
tina-zimnicki merged 5 commits intomainfrom Jan 28, 2026
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub. 2 Skipped Deployments
|
Contributor
Greptile SummaryThis PR adds Content Security Policy (CSP) headers for the Changes include:
The implementation correctly whitelists the necessary external resources (scripts, styles, fonts, images) required for each documentation page to render properly while maintaining security through CSP. Confidence Score: 5/5
Important Files Changed
|
Contributor
Author
|
@gretile pls rereview |
Contributor
Author
|
@greptile pls rereview |
galvana
approved these changes
Jan 28, 2026
Contributor
galvana
left a comment
There was a problem hiding this comment.
Set the environment variable and verified /docs and /redoc don't return any CSP errors in the console
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket ENG-2404
Description Of Changes
Updates CSP header definitions to include docs pages. These were broken when
FIDES__SECURITY__HEADER_MODEwas set torecommended.The changes include domains for scripts, styles, and images that are required for the respective page to load.
Code Changes
/docs/redocSteps to Confirm
FIDES__SECURITY__HEADER_MODE=recommended/docsmake sure the page loads and the console doesn't log any CSP errors/redocmake sure the page loads and the console doesn't log any CSP errorsPre-Merge Checklist
CHANGELOG.mdupdatedmaindowngrade()migration is correct and works