-
-
Notifications
You must be signed in to change notification settings - Fork 65
Open
Description
Hi,
I have not yet created a MVP or anything similar to further dig down, but apparently the recommended settings https://docs.friendlycaptcha.com/#/csp miss a step about the style-src / style-src-elem.
The widget.module.js injects a style element, which is blocked on a page with the following Content-Security-Policy Error in Chrome:
widget.module.min.js:1 Refused to apply inline style because it violates the following Content Security Policy directive: "style-src 'self' 'nonce-rD8UmTfY4BIp0ZHw'". Either the 'unsafe-inline' keyword, a hash ('sha256-DtJ0G5eArSV7tvvFUUeV7iyiWfBGflIkRW64/tmMWUk='), or a nonce ('nonce-...') is required to enable inline execution.
Thanks for confirming or looking into it. I'm happy to provide more information if needed and update this issue.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels