Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Issue Boards

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #14120

Closed (moved)
Open
Opened Jan 06, 2015 by cypherpunks@cypherpunks

Akamai ruleset breaks steamcommunity.com in plaintext HTTP

I get a CSP error when loading steamcommunity urls over HTTP. HTTPS Everywhere has Steam and Steam Community rulesets disabled by default, but Akamai is enabled. Steam's servers send CSP headers for http://akamai when accessed over HTTP, and https://akamai when accessed over HTTPS.

URL tested

http://steamcommunity.com/market

Error message

Content Security Policy: The page's settings blocked the loading of a resource at https://steamcommunity-a.akamaihd.net/public/javascript/modalContent.js?v=XZKI05CNhf-y&l=english ("script-src http://steamcommunity.com 'unsafe-inline' 'unsafe-eval' http://steamcommunity-a.akamaihd.net https://api.steampowered.com http://www.google-analytics.com https://ssl.google-analytics.com").

Workaround

Page works if I enable Steam and Steam Community rulesets.

I am unable to include CSP headers in the ticket description because Trac flags the ticket as spam. If possible, I will include headers in comments.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#14120