Separate log for Content Security Policy Reports
1104
Views
6
Comments
On our RadarOn our Radar
Backend

Currently all CSP messages are in the error log. But would like the see them in a separate log because it is a notification and not an error.

Due to the volume of CSP messages we are likely to miss real errors

CSP?

J.Ja

Sorry, not talking about the Customer Succes Program but the Content Security Policy logs

This is a must have, because the CSReport floods the error logs with messages and it becomes hard to track real errors. Either let us shut it off or redirect it to the security log, which currently (11.8.0) only has "blocked addresses" submenu.

Same here, we are not able to use the error log in production as it is flooded with csreports. 

I agree with Gonçalo here.  

Although, I would not turn off the reporting since these logs can be valuable when tweaking your CSP configurations, the security logs seem a better fit for logging CSP violations.

That would keep the Error logs less flooded :)

It makes a lot of sense to redirect those messages to the security logs.

Being able to shut them down should also be an option, aldo i would not disable it.