Getting deprecation reports from Report-To header; Reports are being generated but not being sent

Viewed 473

Unable to get chrome/any browser to send reports generated with Report-To header

Hi, I am trying to collect Deprecation/Crash/Intervention reports generated by browsers visiting web pages that trigger an event. I have an endpoint set up that currently receives CSP reports when a browser visits the page, but even though there is a deprecation error in the console and in the log viewer a deprecation report has been generated, it is not being sent by chrome (or safari or firefox).

The Report-To header is being delivered, along with the NEL header (which also fails to send reports but is not my focus), as can be seen by scanning my page with securityheaders.com:

enter image description here

(The max age is short here for a test but I have tried with a full year)

Logs

Using chrome://net-export/ and visiting the page with deprecated JS on it, I can see that in the "Per origin config" section the correct information is being set:

correct per origin config

and the deprecated JS is generating deprecation reports:

deprecation reports

but for some reason the reports never send. Sometimes in the log dump it says there have been multiple attempts to send the reports.

Tests

I have tried using chrome with the command-line flags --enable-features=Reporting and --enable-blink-features=Reporting (although I think the three report types are enabled anyway; Intervention, Deprecation and Crash). I have also used safari and firefox and received deprecation alerts in the console but the only reports that are sent are CSP reports.

1 Answers

The Reporting API was designed to be out of band from your web app. The browser captures, queues and batches, then sends reports automatically at the most opportune time. Reports are sent internally by the browser, so there's little to no performance concern (e.g. network contention with your app) when using the Reporting API. There's also no way to control when the browser sends queued reports.

Per the documentation, it doesn't look like this is possible to overcome.

https://developers.google.com/web/updates/2018/09/reportingapi#sending

Related