I keep CSP enabled by default because it should just work for most users and provides security benefits. If you feel we should offer a way to turn it off entirely, can you open an issue on https://gitlab.com/glitchtip/glitchtip-backend it would not be hard to offer such an option.
Turning off Rocket Loader is fine too, I don't think it provides much/any benefit. We already use webpack to bundle code so bundling it again isn't going to make it faster.
Anyone could upload dif to https://app.glitchtip.com ? I have tried to run this command
SENTRY_LOG_LEVEL=debug sentry-cli upload-dif ios-app-particle-setup.app.dSYM/Contents/Resources/DWARF/ios-app-particle-setup
But it got a 403 error with
<h1>Forbidden <span>(403)</span></h1> <p>CSRF verification failed. Request aborted.</p>
[busyness] 30s average busyness is at 70% but we already started maximum number of workers available with current limits (8) .... SIGINT/SIGQUIT received...killing workers... worker 1 buried after 1 seconds worker 2 buried after 1 seconds worker 3 buried after 1 seconds worker 4 buried after 1 seconds worker 5 buried after 1 seconds worker 6 buried after 1 seconds worker 7 buried after 1 seconds worker 8 buried after 1 seconds goodbye to uWSGI.
@benlau it's curious you got a 403 error. As I said file uploads do absolutely nothing at this time. But that response is unexpected. I wonder if your auth key was set up right.
sentry-cli --url https://app.glitchtip.com releases --org test-org --project aaaa files lol upload fun.txt A 6de989b32cb10f2361ddaa46ea917a674429b4c6 (3 bytes)
I haven't begin to explore what upload-dif is for and what API calls it makes.
breaking changes coming to the helm chart - it's now entirely a generic Django chart. The glitchtip helm chart is just a Chart.yaml and values.yaml