Skip to content

Commit 0061d2e

Browse files
committed
Revert "blogs: add CSP report header to blog sites"
This reverts commit 7019e41.
1 parent 7019e41 commit 0061d2e

File tree

4 files changed

+1
-12
lines changed

4 files changed

+1
-12
lines changed

hieradata/environments/production/roles/blogs.yaml

-1
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,6 @@ profile::certbot::certificates:
55

66
profile::wordpress::blogs::admin_email: [email protected]
77
profile::wordpress::blogs::wordpress_version: ~
8-
profile::wordpress::blogs::csp_header: "default-src 'self'; script-src 'self' code.jquery.com; report-uri https://csp-report-api.openjs-foundation.workers.dev/; report-to csp-endpoint"
98
profile::wordpress::blogs::sites:
109
jquery:
1110
host: blog.jquery.com

modules/profile/manifests/wordpress/base.pp

-1
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@
33
String[1] $innodb_buffer_pool_size = lookup('profile::wordpress::base::mariadb_innodb_buffer_pool_size', {default_value => '512M'}),
44
String[1] $wordpress_cli_version = lookup('profile::wordpress::base::wordpress_cli_version'),
55
Optional[String[1]] $default_site_cert = lookup('profile::wordpress::base::default_site_cert', {default_value => undef}),
6-
Optional[String[1]] $csp_header = undef,
76
) {
87
file { '/srv/mariadb':
98
ensure => directory,

modules/profile/manifests/wordpress/blogs.pp

+1-4
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,8 @@
55
String[1] $db_password_seed = lookup('profile::wordpress::blogs::db_password_seed'),
66
Stdlib::Email $admin_email = lookup('profile::wordpress::blogs::admin_email'),
77
String[1] $admin_password = lookup('profile::wordpress::blogs::admin_password'),
8-
String[1] $csp_header = lookup('profile::wordpress::blogs::csp_header'),
98
) {
10-
class { 'profile::wordpress::base':
11-
csp_header => $csp_header,
12-
}
9+
include profile::wordpress::base
1310

1411
git::clone { 'blog.jquery.com-theme':
1512
path => '/srv/wordpress/blog.jquery.com-theme',

modules/profile/templates/wordpress/base/default-tls.nginx.erb

-6
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,6 @@ server {
1414

1515
server_tokens off;
1616

17-
<%- if @csp_header -%>
18-
# Add Content Security Policy headers
19-
add_header Reporting-Endpoints "csp-endpoint='https://csp-report-api.openjs-foundation.workers.dev/'";
20-
add_header Content-Security-Policy-Report-Only "<%= @csp_header %>" always;
21-
<%- end -%>
22-
2317
location /.well-known/acme-challenge {
2418
root /var/www/letsencrypt/;
2519
}

0 commit comments

Comments
 (0)