Red Hat Bugzilla – Bug 1197764
Red Hat Access functionality broken due to Content Security Policy configuration
Last modified: 2017-02-23 15:24:43 EST
Description of problem: The Red Hat Access functionality (KB search, Case management etc) no longer works because the Satellite 6 does not whitelist *redhat.com as a connection destination. Version-Release number of selected component (if applicable): Satellite 6.1 How reproducible: Every time Steps to Reproduce: 1. Log into Satellite UI 2. Navigate to any menu in the Red Hat Access menu in the top right corner 3. Attempt to login into the customer portal Actual results: Login always fails. Javascript console indicates that connection to Red Hat is being blocked due to CSP policy: Content Security Policy: The page's settings blocked the loading of a resource at https://api.access.redhat.com/rs/users/current?redhat_client=foreman_plugin_satellite_0.0.7 ("connect-src https://tongaman.usersys.redhat.com ws: wss:"). Expected results: Connection to *.redhat.com should be allowed Additional info: I have already experimented with a fix that requires changes only in the Red Hat Access plugin
Since this issue was entered in Red Hat Bugzilla, the release flag has been set to ? to ensure that it is properly evaluated for this release.
Fix submitted for next 6.1 beta build
*** Bug 1192325 has been marked as a duplicate of this bug. ***
We can now access all the links related to redhat access. VERIFIED with sat6.1 Beta snap6 compose2.
*** Bug 1192328 has been marked as a duplicate of this bug. ***
This bug is slated to be released with Satellite 6.1.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2015:1592