CentralCSP
APIPolicy Builder

Build a recommended Connection-Allowlist

Builds a Connection-Allowlist for the website from the Connection-Allowlist reports browsers sent over the period, and returns the header value in policy.

Without a policy, it starts from (response-origin), the origin each page is served from. With one, it keeps that allowlist. It then adds each destination browsers reported blocked as its origin, which allows every path on it, and collapses three or more subdomains of one site into a single *. pattern. A reported WebRTC connection turns on webrtc=allow. Browser extensions, anything that is not a plain origin, and noise (a destination reported fewer than 10 times in the period) are left out.

The allowlist ends with report-to=centralcsp. Send reportingEndpoints as the Reporting-Endpoints header alongside it. Connection-Allowlist is new and only Chromium-based browsers support it, so deploy it as Connection-Allowlist-Report-Only first and keep CSP connect-src alongside it.

The period defaults to the last 7 days and covers up to 30.

Anyone who knows the reporting endpoint can send reports to it, so a destination in the result is not proof that your pages connect to it. Review the added destinations before deploying: allowing a destination lets a script send data there.

Limited to 10 requests a minute for each person, after which it answers 429 with a Retry-After header.

Requires the viewer role on the website and the report:connection-allowlist plan feature.

POST
/v1/workspaces/{workspaceId}/websites/{websiteId}/connection-allowlist/recommended-policy

Authorization

AuthorizationBearer <token>

An OpenID Connect access token from signing in to CentralCSP, acting as the signed-in user.

In: header

Path Parameters

workspaceId*string

The workspace's id.

websiteId*string

The website's id.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

The period of reports to learn from and, optionally, the allowlist to start from.

range?string

How far back to read reports, counted from now. Defaults to 7d and is ignored when from and to are given.

Value in

  • "24h"
  • "7d"
  • "14d"
  • "30d"
from?string

Start of a calendar period instead of range. It must fall within the last 30 days and comes with to.

Formatdate-time
to?string

End of the calendar period, exclusive. It comes with from.

Formatdate-time
policy?string

The allowlist to start from, as a Connection-Allowlist header value without the header name. Leave it out to start from (response-origin).

Length1 <= length <= 16384

Response Body

application/json

curl -X POST "https://example.com/v1/workspaces/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/websites/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/connection-allowlist/recommended-policy" \  -H "Content-Type: application/json" \  -d '{}'
{  "policy": "(response-origin \"https://api.example.com\" \"https://*.cdn.example.com\"); report-to=centralcsp",  "reportingEndpoints": "centralcsp=\"https://e0123456789abcdef0123.report.centralcsp.com\", default=\"https://e0123456789abcdef0123.report.centralcsp.com\""}