CSP headers and javascripts
-
Hi,
do you have kind of solutions to using CSP headers and loading javascript deferred? None of the scripts work if deferred is on.
Without CSP policy they work just fine using deferred loading
Thanks!
content-security-policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://googletagmanager.com/ https://embed.tawk.to https://*.google.co.uk https://*.klarna.com/ https://*.ukrsolution.com https://*.googletagmanager.com/ https://tagmanager.google.com/ https://*.klarnacdn.net https://google.com/ https://*.google.com/ https://www.google-analytics.com/ https://connect.facebook.net/ https://*.tawk.to https://www.googletagmanager.com https://*.googleadservices.com/ https://googleads.g.doubleclick.net/ https://stats.wp.com/ https://cdnjs.cloudflare.com; img-src 'self' data: https://googletagmanager.com/ https://embed.tawk.to https://*.google.co.uk https://*.wp.com https://*.klarnacdn.net https://*.googletagmanager.com/ https://gstatic.com/ https://*.gstatic.com/ https://googleads.g.doubleclick.net/ https://google.com/ https://*.google.com/ https://www.facebook.com/ https://www.google-analytics.com/ https://www.google.fi/; object-src 'self' data: https://*.youtube.com/ https://embed.tawk.to https://*.google.co.uk https://*.youtube-nocookie.com/ https://youtu.be/ https://*.vimeo.com/ https://connect.facebook.net/ https://www.facebook.com/; frame-src 'self' data: https://*.youtube.com/ https://*.youtube-nocookie.com/ https://*.google.co.uk https://embed.tawk.to https://youtu.be/ https://*.klarna.com/ https://*.vimeo.com/ https://connect.facebook.net/ https://www.facebook.com/;
The topic ‘CSP headers and javascripts’ is closed to new replies.