-
-
Notifications
You must be signed in to change notification settings - Fork 6.3k
Closed
Description
Version
3.0.0-beta.6
Steps to reproduce
vue create testapp
- Setup as you want.
- Add
productionSourceMap: false
in vue.config.js. - Build and push dist folder to your server.
- Add CSP header in your server config.
Content-Security-Policy-report-only "default-src 'none'; script-src 'self'; img-src 'self' data:; style-src 'self' ";
- Open the app in browser
What is expected?
according to the Vuejs doc there should be no problem
What is actually happening?
The page return an error
[Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-aMW8RJ8d9m3crvBSAvcz8B/pG hlL4Sa2UuvzcOXfAE='), or a nonce ('nonce-...') is required to enable inline execution.
Do you have an idea to get around this?
blexxed
Metadata
Metadata
Assignees
Labels
No labels