polyfill.io was crazy huh, we just let a third party run any JS without even checking integrity. lol

anyway please add this snippet for google tag manager, marketing needs it

@mxbck It's super hard to implement a good Content-Security-Policy when people use GTM.
@frederic been down that road too. Frustrating to say the least 😅

@frederic @mxbck

I wanted to build a service for that in 2018, but never did. But others did now.

https://csper.io/
https://developers.cloudflare.com/page-shield/policies/

I thought of a painful progress like:

- Hey, you added stuff via GTM and it will not work
- We blocked all that. Which are your requests and why do you need it -> documentation done
- Do the developers & management approve the adding of the new item?

If you force me to use jira, I will force you to request tracking stuff via a 10 step process.

Csper: Content Security Policy made easy

Content-Security-Policy made easy. Build, deploy, and monitor your Content Security Policy today. The most advance tools for maintaining content security policy.

Csper
@hellpat @frederic @mxbck I was going to share a link to a chrome extension I built a few years ago for generating CSPs based on the current page's resources, but it looks like Caspr blows it out of the water 😂 fair play. It even has graphs and colours. Thanks for sharing.
@mxbck I can do you one worse. Marketing have access to GTM and can add whatever they want...
@Spence1115 @mxbck ... and everything they add shows up as a red thread-blocking bar in the browser's performance tools.
@carey @mxbck then a bug comes in complaining the site is too slow, coming from... Marketing!

@mxbck

*pastes this into slack*

*slack links the domain polyfill dot io*

@mxbck wget http://some-website/install | sh
@mxbck Google Tag Manager should be blocked at the ISP level. Convince me otherwise.
@mxbck nevermind that it’s also a GDPR violation #DSGVO