Skip to content

Google Analytics CSP Violation #30880

Closed
@zaximus84

Description

@zaximus84

Preconditions (*)

  1. Magento 2.4.0
  2. Magento_Csp installed / enabled
  3. Magento_GoogleAnalytics installed / enabled

Steps to reproduce (*)

  1. In admin store configuration, go to Sales / Google API > Google Analytics. Set Enabled = Yes and enter an Account Number.
  2. Flush all caches and load a page on the store front (such as the home page).

Expected result (*)

  1. There are no console errors / failed assets or requests due to CSP violations.

Actual result (*)

  1. There is a console error regarding a CSP violation for an XHR request to https://www.google-analytics.com/j/collect. If CSP is in report-only mode, it's just a console error. If CSP is actually enforced, the XHR request is not executed.

Please provide Severity assessment for the Issue as Reporter. This information will help during Confirmation and Issue triage processes.

  • Severity: S0 - Affects critical data or functionality and leaves users without workaround.
  • Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.
  • Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.
  • Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.
  • Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.

Metadata

Metadata

Assignees

Labels

Component: CspFixed in 2.4.xThe issue has been fixed in 2.4-develop branchIssue: ConfirmedGate 3 Passed. Manual verification of the issue completed. Issue is confirmedPriority: P2A defect with this priority could have functionality issues which are not to expectations.Progress: doneReproduced on 2.4.xThe issue has been reproduced on latest 2.4-develop branchSeverity: S2Major restrictions or short-term circumventions are required until a fix is available.

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions