Refused to load the script because it violates the following Content Security Policy directive: script-src self https: unsafe-eval unsafe-inline

Viewed 306

I actually have a problem with Content Security Policy.

I want to install Mixpanel on my ruby site so I followed their tutorial and tried to add a simple tracker :

<script type="text/javascript">
  mixpanel.track("Page Loaded");
</script>

And that's where everything start to go wrong. This error appears in the console :

Refused to load the script 'http://cdn4.mxpnl.com/libs/mixpanel-2-latest.min.js' because it violates the following Content Security Policy directive: "script-src 'self' https: 'unsafe-eval' 'unsafe-inline'".

First I thought I messed up my copy-paste, because I never heard about CSP before, I checked my project token and my script, but everything is fine on this side. I tried to look around about this error and possible solutions (even tried <meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'">, just in case) , but I couldn't find a way to make it work without adding more refused script / images.

Someone know how I could make it work ?

0 Answers
Related