From 8f970e1e573099ce95bae37f6b2fcb2ea73c1b21 Mon Sep 17 00:00:00 2001 From: erdgeist Date: Sun, 19 Jul 2026 01:50:13 +0200 Subject: Add a 500er logger and a trip wire in admin/boom to test it --- app/controllers/csp_reports_controller.rb | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) (limited to 'app/controllers/csp_reports_controller.rb') diff --git a/app/controllers/csp_reports_controller.rb b/app/controllers/csp_reports_controller.rb index 08cbc98..a8f8edb 100644 --- a/app/controllers/csp_reports_controller.rb +++ b/app/controllers/csp_reports_controller.rb @@ -3,8 +3,20 @@ class CspReportsController < ApplicationController skip_before_action :verify_authenticity_token def create - report = request.body.read(8192) - Rails.logger.warn("CSP violation: #{report}") if report.present? + request.body.rewind if request.body.respond_to?(:rewind) + raw = request.body.read(8192) + raw = request.raw_post if raw.blank? + + report = (JSON.parse(raw)["csp-report"] rescue nil) + + if report + directive = report["effective-directive"] || report["violated-directive"] + at = (URI.parse(report["document-uri"]).path rescue "unparsed") + Rails.logger.warn("CSP violation: #{directive} blocked=#{report['blocked-uri']} at=#{at}") + else + Rails.logger.warn("CSP violation: unparseable report (#{raw.to_s.bytesize} bytes)") + end + head :no_content end end -- cgit v1.3