From 3b6656353fd34056f4a08706f0fe463a6ac77392 Mon Sep 17 00:00:00 2001 From: gwarser Date: Fri, 10 Dec 2021 01:27:21 +0100 Subject: [PATCH] People are afraid of CSP, recommend to disable it by `@@||*^$csp`, this needs clarification. --- Static-filter-syntax.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/Static-filter-syntax.md b/Static-filter-syntax.md index 949a62f..3bc0e25 100644 --- a/Static-filter-syntax.md +++ b/Static-filter-syntax.md @@ -523,8 +523,9 @@ Exception filter for specific `csp` blocking filter must have exactly the same c @@||example.com^$csp -CSP option syntax may look unusual compared to other filters. It works mostly in "allowlist" mode - data can be downloaded only from addresses explicitly specified in this option. Refer to ["Content Security Policy (CSP) -Quick Reference Guide"](https://content-security-policy.com/) or [MDN documentation](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy) for further syntax help. +CSP option syntax may look unusual compared to other filters. It's advised to be used only by advanced users. It works in "allowlist" mode - data can be downloaded only from addresses explicitly specified in this option. However, uBO is adding it's own second CSP header, which [as per specification](https://w3c.github.io/webappsec-csp/#multiple-policies) will be merged into one final policy, which will be in sum enforcing most strict rules from both headers. For example, you can easily break webpage if policy send by server allows `a.com` and `b.com` and your filter adds `c.com` - in sum, no request will be allowed at all. + +Refer to ["Content Security Policy (CSP) Quick Reference Guide"](https://content-security-policy.com/) or [MDN documentation](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy) for further syntax help. See also [`denyallow`](#denyallow).