certsimple / csp-by-api

Significantly cuts down on CSP policy management by specifying common APIs by name.
17 stars 6 forks source link

Google Tag Manager #3

Open novemberborn opened 7 years ago

novemberborn commented 7 years ago

Google seems to be recommending a new snippet for setting up analytics: https://developers.google.com/analytics/devguides/collection/gtagjs/

I think this means https://www.googletagmanager.com should be whitelisted. I'm not sure if this should be a separate entry or if it can be added to the existing googleAnalytics service. There's a lot of domains in there already which seems unnecessary?

Note that events are sent to https://www.google-analytics.com through img-src.

mikemaccana commented 7 years ago

I'd add it a separate googleGlobalSiteTag as users of this and googleAnalytics won't necessarily need the other one. Thanks Wuubs! 👍

novemberborn commented 7 years ago

Heh haven't been called that in a while 😉

Unfortunately I'm wrapping up this contract today so I won't have time to follow up on this. Anybody reading this please feel free to pick this up!

mikemaccana commented 7 years ago

I'd like to add this, but really need to have someone using Google Tag Manager to test it (my time's a little limited). If you use GTM let me know and we'll go from there!