Skip to content

Commit 76e2e04

Browse files
author
Deepak Pandey
committed
Fix CSP violations: Allow inline scripts/styles and Cloudflare Insights
- Added 'unsafe-inline' to script-src for Next.js inline scripts - Added 'unsafe-eval' to script-src for dynamic script evaluation - Added 'unsafe-inline' to style-src for Google Fonts and inline styles - Added https://static.cloudflareinsights.com to script-src for Cloudflare Analytics - This resolves the 35+ CSP violations preventing site from loading properly
1 parent ef38cce commit 76e2e04

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

vercel.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@
7373
},
7474
{
7575
"key": "Content-Security-Policy",
76-
"value": "default-src 'self'; script-src 'self' https://vercel.live https://va.vercel-scripts.com; style-src 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https: blob:; connect-src 'self' https://*.supabase.co https://*.vercel.app wss://*.supabase.co; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;"
76+
"value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://vercel.live https://va.vercel-scripts.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https: blob:; connect-src 'self' https://*.supabase.co https://*.vercel.app wss://*.supabase.co; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;"
7777
}
7878
]
7979
}

0 commit comments

Comments
 (0)