Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP violation on https://testrp.security.allizom.org/ #242

Open
claudijd opened this issue Nov 1, 2018 · 1 comment
Open

CSP violation on https://testrp.security.allizom.org/ #242

claudijd opened this issue Nov 1, 2018 · 1 comment

Comments

@claudijd
Copy link
Contributor

claudijd commented Nov 1, 2018

@gene1wood and I were testing something unrelated and noticed a CSP violation on this endpoint when following the "Nginx+Lua with Social, LDAP and Passwordless options" login option.

Here's a demo of the behavior, which triggers prior to actual login:

screen_shot_2018-11-01_at_12_37_57_pm

Please note that the destination URL is auth0.org (and not auth0.com).

@gene1wood
Copy link
Contributor

@viorelaioia We should probably establish a test for this type of thing. @hidde I don't see auth0.org in the codebase so I'm unsure where this is coming from.

What UX symptoms would we see from the connection list for the client-id failing like this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants