IP address comes from 3.235.xx.xx. It access the URL of my Netlify (preview site?) https://5f1553a0a5e2da5f8387fffe--lucid-lamarr-eeb067.netlify.app
It may be related to Netlify prerender function. I am not sure.
I had CSP in place, the production site works fine. The violation (CSS/JS) triggers two alarms to my CSP software.
Please take a look, thanks.
{
“csp-report”: {
“line_number”: 96,
“blocked_uri”: “https://www.kappawingman.com/theme/css/copybutton.css”,
“script_sample”: “”,
“status_code”: 0,
“violated_directive”: “style-src-elem”,
“document_uri”: “https://random-number-my-random-url-in-netlify/”,
“original_policy”: “default-src ‘self’ https://disqus.com https://c.disquscdn.com ; manifest-src ‘self’; script-src ‘self’ ‘unsafe-inline’ ‘unsafe-eval’ https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com https://kappa-wingman.disqus.com/embed.js https://kappa-wingman.disqus.com/count.js https://c.disquscdn.com https://www.google-analytics.com https://storage.googleapis.com https://api.github.com; img-src ‘self’ https://* https://www.google-analytics.com https://webmention.io https://res.cloudinary.com; style-src ‘self’ ‘unsafe-inline’ https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://c.disquscdn.com; font-src ‘self’ https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com; connect-src ‘self’ https://o417064.ingest.sentry.io https://meilisearch.kappawingman.com https://kappa-meilisearch.herokuapp.com https://webmention.io https://s3-us-west-2.amazonaws.com/ca3db/ https://c.disquscdn.com https://kappa-wingman.disqus.com wss://realtime.services.disqus.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com https://fonts.googleapis.com https://fonts.gstatic.com https://res.cloudinary.com; frame-ancestors ‘self’; base-uri ‘self’; form-action ‘self’ https://webmention.io; media-src ‘none’; object-src ‘none’; block-all-mixed-content;”,
“source_file”: “https://random-number-my-random-url-in-netlify/”,
“disposition”: “enforce”,
“referrer”: “”,
“effective_directive”: “style-src-elem”
}
}
{
“csp-report”: {
“blocked_uri”: “https://www.kappawingman.com/theme/js/util.js?v=v1.9.3”,
“script_sample”: “”,
“status_code”: 0,
“violated_directive”: “script-src-elem”,
“document_uri”: “https://random-number-my-random-url-in-netlify/”,
“original_policy”: “default-src ‘self’ https://disqus.com https://c.disquscdn.com ; manifest-src ‘self’; script-src ‘self’ ‘unsafe-inline’ ‘unsafe-eval’ https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com https://kappa-wingman.disqus.com/embed.js https://kappa-wingman.disqus.com/count.js https://c.disquscdn.com https://www.google-analytics.com https://storage.googleapis.com https://api.github.com; img-src ‘self’ https://* https://www.google-analytics.com https://webmention.io https://res.cloudinary.com; style-src ‘self’ ‘unsafe-inline’ https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://c.disquscdn.com; font-src ‘self’ https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com; connect-src ‘self’ https://o417064.ingest.sentry.io https://meilisearch.kappawingman.com https://kappa-meilisearch.herokuapp.com https://webmention.io https://s3-us-west-2.amazonaws.com/ca3db/ https://c.disquscdn.com https://kappa-wingman.disqus.com wss://realtime.services.disqus.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com https://fonts.googleapis.com https://fonts.gstatic.com https://res.cloudinary.com; frame-ancestors ‘self’; base-uri ‘self’; form-action ‘self’ https://webmention.io; media-src ‘none’; object-src ‘none’; block-all-mixed-content;”,
“disposition”: “enforce”,
“referrer”: “”,
“effective_directive”: “script-src-elem”
}
}