Skip to content
This repository has been archived by the owner on Jan 10, 2024. It is now read-only.

Content Security Policy Directive #24

Open
caseyboyd opened this issue Aug 20, 2018 · 2 comments
Open

Content Security Policy Directive #24

caseyboyd opened this issue Aug 20, 2018 · 2 comments

Comments

@caseyboyd
Copy link

Refused to execute JavaScript URL because it violates the following Content Security Policy directive: "script-src 'self' 'nonce-5310cb31-6b69-5584-26e5-3bd833131f97' chrome-extension: 'unsafe-eval' https://sfdc.azureedge.net *.na57.visual.force.com 'unsafe-eval' https://ssl.gstatic.com/accessibility/". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution.

Getting this error when executing "sforce.opencti.screenPop"

Any ideas?

@nikhilcloudroute
Copy link

@caseyboyd did you find any solution to this? I am still facing this issue.

@kishoreaoe
Copy link

for development purpose, i have installed CSP plugin in chrome and going forward. @caseyboyd @nikhilcloudroute hope this may helps.

As far as i know we need to write .htaccess rule and need to add these values inside it.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants