I actually have a problem with Content Security Policy.
I want to install Mixpanel on my ruby site so I followed their tutorial and tried to add a simple tracker :
<script type="text/javascript">
mixpanel.track("Page Loaded");
</script>
And that's where everything start to go wrong. This error appears in the console :
Refused to load the script 'http://cdn4.mxpnl.com/libs/mixpanel-2-latest.min.js' because it violates the following Content Security Policy directive: "script-src 'self' https: 'unsafe-eval' 'unsafe-inline'".
First I thought I messed up my copy-paste, because I never heard about CSP before, I checked my project token and my script, but everything is fine on this side. I tried to look around about this error and possible solutions (even tried <meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'">, just in case) , but I couldn't find a way to make it work without adding more refused script / images.
Someone know how I could make it work ?