
TD Bank Group
Last activity: 1 Mar 2018 11:11 EST
Content Security Policy - wss protocol on Self is being blocked
We have implemented a custom CSP for our application, and for the connect-src directive, we set it to Self.
We are now seeing items being blocked and reported with a Blocked Content Source of wss:// where is the same domain as the Pega instance.
We would have expected the "Self" option to match for the wss protocol as well.
If that's not the case, can we provide an "Allowed website" with a wildcard like wss://* as this domain will change per environment.