CSP error from `util.js:157:9` for missing unsafe-eval

(#590) Bug Needs triage security self-hosting

Summary

image Content-Security-Policy: The page’s settings blocked a JavaScript eval (script-src) from being executed because it violates the following directive: “script-src 'self' 'nonce-a26580da56f6096b44e5980c8834bffd' 'wasm-unsafe-eval' blob: https://*.fluxer.app https://hcaptcha.com https://*.hcaptcha.com https://fluxer.group” (Missing 'unsafe-eval')

Steps to reproduce

  1. load fluxer.group hosted on cloudflare with proxy on
  2. check console. happens 100% of the time.
  • 608579011-775643bf-aa46-4124-9c72-129f440509e5.png

    608579011-775643bf-aa46-4124-9c72-129f440509e5.png

    2280×245 | 59 kB

0 comments

Sign in with Fluxer to comment and vote.
Deleted comment
Removed by moderator Rex: Removed a general status note that was posted on many GitHub threads. It no longer applies here.