notes icon indicating copy to clipboard operation
notes copied to clipboard

Content Security Policy blocks app from loading

Open strugee opened this issue 8 years ago • 4 comments

When I load the just-installed Notes app on my server, I get the following security error in my console:

Content Security Policy: The page's settings blocked the loading of a resource at self ("script-src https://cloud.strugee.net 'unsafe-eval'").

All I see is a white screen in ownCloud, with the + for "new note" barely visible. I'm running ownCloud 8.2.2 and Notes 2.0.0. ownCloud is sending the following HTTP header with the first response:

content-security-policy: "default-src 'none';script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: *;font-src 'self';connect-src 'self';media-src 'self'"

strugee avatar Jan 15 '16 09:01 strugee