diff --git a/.changeset/eight-adults-joke.md b/.changeset/eight-adults-joke.md new file mode 100644 index 0000000000..ffda738213 --- /dev/null +++ b/.changeset/eight-adults-joke.md @@ -0,0 +1,5 @@ +--- +'@backstage/plugin-analytics-module-ga': patch +--- + +Added CSP instructions to README diff --git a/plugins/analytics-module-ga/README.md b/plugins/analytics-module-ga/README.md index 92cfd7e9ae..4b822ea3e3 100644 --- a/plugins/analytics-module-ga/README.md +++ b/plugins/analytics-module-ga/README.md @@ -47,6 +47,19 @@ app: trackingId: UA-0000000-0 ``` +4. Update CSP in your `app-config.yaml`: + +The following is the minimal content security policy required to load scripts from GA. + +```yaml +backend: + csp: + connect-src: ["'self'", 'http:', 'https:'] + # Add these two lines below + script-src: ["'self'", "'unsafe-eval'", 'https://www.google-analytics.com'] + img-src: ["'self'", 'data:', 'https://www.google-analytics.com'] +``` + ## Configuration In order to be able to analyze usage of your Backstage instance _by plugin_, we