4 ms·
Kind of ironic (Firefox): http://i.imgur.com/p6RDBb4.png http://i.imgur.com/p6RDBb4.png This is also keeping the CSS from loading. (Chrome, however, displays b
by sarciszewski 11y ago
Kind of ironic (Firefox): http://i.imgur.com/p6RDBb4.png http://i.imgur.com/p6RDBb4.png
This is also keeping the CSS from loading. (Chrome, however, displays beautifully.)
- tombrossman 11y agoStrange, I get the same thing too despite the domain being among those whitelisted. I don't know how 'self' cannot equal securityheaders.io for a request to that domain. I remember a while back when I was first using this I had a really difficult time getting it to work for a site I was doing. In the end, I had to remove all references to 'self' as a source and use the domain instead (even though these should be one and the same).
- sarciszewski 11y agoIt's probably a Firefox bug.
- Scott_Helme_ 11y agoInteresting, what version of Firefox is this? You can see in the CSP that 'self' is a defined keyword for both the script-src and style-src directives: https://report-uri.io/home/analyse/https%3A%2F%2Fsecurityheaders.io%2F https://report-uri.io/home/analyse/https%3A%2F%2Fsecurityhea...
- sarciszewski 11y ago44.0, but as it turns out, an update is available.
- Scott_Helme_ 11y agoDid that fix it? Failing that, do you have any extensions or other things that might affect this?
- sarciszewski 11y agoYour latest change allowed me to whitelist azureedge.net in RequestPolicy. All of them say "A CSP report is being sent."