【问题标题】:content security policy error, but meta-tag includes URL内容安全策略错误,但元标记包含 URL
【发布时间】:2015-07-06 21:56:00
【问题描述】:

为什么我会收到这样的错误?

Refused to load the script 'http://maps.googleapis.com/maps/api/js?v=3&sensor=false'


because it violates the following Content Security Policy directive: 
"script-src 'self' *.googleapis.com 'unsafe-inline' 'unsafe-eval'".

我的元标记:

<meta http-equiv="Content-Security-Policy" 
content="default-src *; style-src 'self' *.googleapis.com 'unsafe-inline'; script-src 'self' *.googleapis.com 'unsafe-inline' 'unsafe-eval'">

【问题讨论】:

    标签: android ionic-framework content-security-policy


    【解决方案1】:

    似乎我需要明确的 URI 方案。这项工作:

    <meta http-equiv="Content-Security-Policy"
          content="default-src *;
                   script-src 'self' 'unsafe-inline' 'unsafe-eval'
                               127.0.0.1:*
                               http://*.gstatic.com
                               http://*.googleapis.com
                               https://*.gstatic.com
                               https://*.googleapis.com
                               ;
                   style-src  'self' 'unsafe-inline'
                               127.0.0.1:*
                               http://*.gstatic.com
                               http://*.googleapis.com
                               https://*.gstatic.com
                               https://*.googleapis.com
    ">
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2021-12-25
      • 1970-01-01
      • 2015-09-17
      • 1970-01-01
      • 1970-01-01
      • 2017-05-11
      • 2016-03-11
      • 2021-03-13
      相关资源
      最近更新 更多