certsimple / csp-by-api

Significantly cuts down on CSP policy management by specifying common APIs by name.
17 stars 6 forks source link

Add carbonads support #5

Open XhmikosR opened 6 years ago

mikemaccana commented 6 years ago

Send a PR!

mikemaccana commented 6 years ago

Did you send a PR?

XhmikosR commented 6 years ago

As you clearly see, no. There is no clear list of hosts they are serving ads from. Or at least one, I'm aware of.

mikemaccana commented 6 years ago

No problem. To make a PR adding support for CarbonAds:

XhmikosR commented 6 years ago

I have already asked them and they haven't a clear list of hosts. Which is very annoying because I have to see the failures by myself. Anyway, my current CSP is https://github.com/MaxCDN/bootstrapcdn/blob/develop/config/helmet-csp.js