Hey I have an Ror App and I've set the CSP in my app globaly this is CSP file in my config/initilaizers/content_security_policy
Rails.application.config.content_security_policy do |policy|
policy.default_src :self, :https
policy.font_src :self, :https, :data
policy.img_src :self, :https, :data
policy.object_src :none
policy.script_src :self, :https
policy.style_src :self, :https
end
but I have a problem with ckeditor and google font
1st google font wont loaded the font
2nd ckeditor have an error on the style like this
ckeditor.js:94 Refused to apply inline style because it violates the following Content Security Policy directive: "style-src 'self' https:". Either the 'unsafe-inline' keyword, a hash ('sha256-ZVjd2zfSTfAVh1y7eCcNk0SPGUQOP/H8vzrFJIVgg90='), or a nonce ('nonce-...') is required to enable inline execution.
the question is, can I add specific unsafe_inline only for ckeditor CSP ? this is because I only use this CKEditor only in rails_admin
and why the google font wont loaded after I generated integrity hash?
thanks