rails content-security-policy for script-src impedes activity

Viewed 94

The browser console is hitting some errors due to content security policy on a Rails 7.0.3 application when running connections to localhost:3000.

Rails.application.config.content_security_policy do |policy|
#   policy.default_src :self, :https
   policy.font_src    :self, :https, :data
   policy.img_src     :self, :https, :data
   policy.object_src  :none
   policy.style_src   :self, :https, :unsafe_inline
   policy.connect_src :self, :https, 'https://api.stripe.com'
   policy.frame_src   :self, 'https://js.stripe.com', 'https://hooks.stripe.com'
#   policy.script_src  :self, :https #, :unsafe_inline
end

Under the above settings the application does not encounter any errors.
The moment one of the two disabled policies is enabled, page settings block elements Content Security Policy: The page's settings blocked the loading of a resource at inline ("script-src"). The peculiar part is that it occurs even with default settings

   policy.script_src  :self, :https

Also, it is weird that default_src would also lead to blocking of said resource...

[side note] no idea how to get this suggestion to function, the path being a rails-compliant route definition

   # Specify URI for violation reports
   # policy.report_uri "/csp-violation-report-endpoint"

The first line points to the place where the first object is blocked, essentially the application importmap thus disabling hotwire. enter image description here wonderful!

The question is a bit fuzzy (knowledge of csp combined with the mechanics of Rails and importmaps in this instance being limited). The full set of policies are running on a Rails 6 application; Rails 7 has the obvious change of importmaps to do things the Hotwire way. The lack of a CSP, especially regarding scripts, is logically frowned upon.

So how does Hotwire get to run with proper settings?

0 Answers
Related