Summary
App stability completely fails when noscript is active. Even though every part of the site is trusted.
Errors like:
patchWorkers.main.js:381 Creating a worker from '
https://web.fluxer.app/sw.js?v=[whatever]%27 violates the following Content Security Policy directive: "script-src 'none'". Note that 'worker-src' was not explicitly set, so 'script-src' is used as a fallback. The policy is report-only, so the violation has been logged but no further action has been taken.
seem to show the spark of a cascade failure based on reproduction steps. The web app either crashes or the section that's being updated turns blank. Generally, it causes many things to not load properly because of this specific block, making the app pretty much inoperable as a result.
Since this is a web app issue exacerbated by an extremely protective extension, it's not that big an issue, just mark it as low priority and fix it when other stability issues and bugs are patched.
Steps to reproduce
open the fluxer web app with noscript (everything trusted) and ublock origin active.
Try doing something that would update the screen
This includes: changing servers, changing to dm's, sending a message, finishing creation of a new channel, changing channels, trying to join a server, changing settings in the dropdown, and joining a vc.
This does not include: opening the settings dropdown in a server, or opening the explore page.
Environment (optional)
Browser: Brave (shields off)
Extensions: Ublock Origin (active), noscript (everything trusted)
Logs or screenshots (optional)
Error with Permissions-Policy header: Unrecognized feature: 'browsing-topics'.
Error with Permissions-Policy header: Unrecognized feature: 'run-ad-auction'.
Error with Permissions-Policy header: Origin trial controlled feature not enabled: 'join-ad-interest-group'.
Error with Permissions-Policy header: Unrecognized feature: 'private-state-token-redemption'.
Error with Permissions-Policy header: Unrecognized feature: 'private-state-token-issuance'.
Error with Permissions-Policy header: Unrecognized feature: 'private-aggregation'.
Error with Permissions-Policy header: Unrecognized feature: 'attribution-reporting'.
VM1222:18 callback globalThis.ns_setupCallback is not a function (undefined).
Executing inline script violates the following Content Security Policy directive 'script-
https://web.fluxer.app/channels/[community ID]/[channel ID in community](shown as [19 didget number]:1)-src-elem 'none''. Either the 'unsafe-inline' keyword, a hash ('sha256-[insert hash here]='), or a nonce ('nonce-...') is required to enable inline execution. The policy is report-only, so the violation has been logged but no further action has been taken.
19 instances of:
Loading the script '<URL>' violates the following Content Security Policy directive: "script-src-elem 'none'". The policy is report-only, so the violation has been logged but no further action has been taken.
164 instances of:
Loading the font '<URL>' violates the following Content Security Policy directive: "font-src 'none'". The policy is report-only, so the violation has been logged but no further action has been taken.
[some ID].ingest.us.sentry.io/api/[probably your api]/envelope/?sentry_version=7&sentry_key=[key here]&sentry_client=sentry.javascript.react%2F10.39.0:1 Failed to load resource: net::ERR_BLOCKED_BY_CLIENT
patchWorkers.main.js:381 Creating a worker from '
https://web.fluxer.app/sw.js?v=[some string]' violates the following Content Security Policy directive: "script-src 'none'". Note that 'worker-src' was not explicitly set, so 'script-src' is used as a fallback. The policy is report-only, so the violation has been logged but no further action has been taken.
//self made note here: patchWorkers.main.js of noscript seems to be the culprit for all of this.
//self made note here: other errors don't really matter as it's easy to replicate and I'm manually pasting from console.
Checks
- ☑ I searched for existing issues and didn't find a duplicate.