@@ -97,41 +97,41 @@ public function provideRequestAndResponsesForOnKernelResponse()
97
97
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
98
98
$ this ->createRequest (),
99
99
$ this ->createResponse (),
100
- array ('Content-Security-Policy ' => null , 'X-Content-Security-Policy ' => null ),
100
+ array ('Content-Security-Policy ' => null , 'Content-Security-Policy-Report-Only ' => null , ' X-Content-Security-Policy ' => null ),
101
101
),
102
102
array (
103
103
$ nonce , array ('csp_script_nonce ' => $ requestScriptNonce , 'csp_style_nonce ' => $ requestStyleNonce ),
104
104
$ this ->createRequest ($ requestNonceHeaders ),
105
105
$ this ->createResponse ($ responseNonceHeaders ),
106
- array ('Content-Security-Policy ' => null , 'X-Content-Security-Policy ' => null ),
106
+ array ('Content-Security-Policy ' => null , 'Content-Security-Policy-Report-Only ' => null , ' X-Content-Security-Policy ' => null ),
107
107
),
108
108
array (
109
109
$ nonce ,
110
110
array ('csp_script_nonce ' => $ requestScriptNonce , 'csp_style_nonce ' => $ requestStyleNonce ),
111
111
$ this ->createRequest ($ requestNonceHeaders ),
112
112
$ this ->createResponse (),
113
- array ('Content-Security-Policy ' => null , 'X-Content-Security-Policy ' => null ),
113
+ array ('Content-Security-Policy ' => null , 'Content-Security-Policy-Report-Only ' => null , ' X-Content-Security-Policy ' => null ),
114
114
),
115
115
array (
116
116
$ nonce ,
117
117
array ('csp_script_nonce ' => $ responseScriptNonce , 'csp_style_nonce ' => $ responseStyleNonce ),
118
118
$ this ->createRequest (),
119
119
$ this ->createResponse ($ responseNonceHeaders ),
120
- array ('Content-Security-Policy ' => null , 'X-Content-Security-Policy ' => null ),
120
+ array ('Content-Security-Policy ' => null , 'Content-Security-Policy-Report-Only ' => null , ' X-Content-Security-Policy ' => null ),
121
121
),
122
122
array (
123
123
$ nonce ,
124
124
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
125
125
$ this ->createRequest (),
126
- $ this ->createResponse (array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' )),
127
- array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' , 'X-Content-Security-Policy ' => null ),
126
+ $ this ->createResponse (array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' , ' Content-Security-Policy-Report-Only ' => ' frame-ancestors http: ; form-action: http: ' )),
127
+ array ('Content-Security-Policy ' => 'frame-ancestors https: ; form-action: https: ' , 'Content-Security-Policy-Report-Only ' => ' frame-ancestors http: ; form-action: http: ' , ' X-Content-Security-Policy ' => null ),
128
128
),
129
129
array (
130
130
$ nonce ,
131
131
array ('csp_script_nonce ' => $ nonce , 'csp_style_nonce ' => $ nonce ),
132
132
$ this ->createRequest (),
133
- $ this ->createResponse (array ('Content-Security-Policy ' => 'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'' )),
134
- array ('Content-Security-Policy ' => 'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'; style-src \'self \' domain.com \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' , 'X-Content-Security-Policy ' => null ),
133
+ $ this ->createResponse (array ('Content-Security-Policy ' => 'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'' , ' Content-Security-Policy-Report-Only ' => ' default-src \' self \' domain-report-only.com; script-src \' self \' \' unsafe-inline \'' )),
134
+ array ('Content-Security-Policy ' => 'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'; style-src \'self \' domain.com \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' , 'Content-Security-Policy-Report-Only ' => ' default-src \' self \' domain-report-only.com; script-src \' self \' \' unsafe-inline \' ; style-src \' self \' domain-report-only.com \' unsafe-inline \' \' nonce- ' . $ nonce . '\'' , ' X-Content-Security-Policy ' => null ),
135
135
),
136
136
array (
137
137
$ nonce ,
0 commit comments