Skip to content

Conversation

@tstirrat15
Copy link
Collaborator

Description

image

The issue here is that the JS for the search bar is dynamically imported, and it comes from the CDN domain, not from authzed.com. Chrome (though interestingly not firefox) treats this as a CSP violation even without a CSP set; setting an explicit CSP should fix this.

Changes

  • Add a simple CSP that sets default-src to include our CDN

Testing

Review

@vercel
Copy link
Contributor

vercel bot commented Dec 8, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
docs Ready Ready Preview Comment Dec 8, 2025 1:40am

@tstirrat15 tstirrat15 marked this pull request as ready for review December 8, 2025 01:40
@tstirrat15 tstirrat15 merged commit 238e324 into main Dec 8, 2025
9 of 10 checks passed
@tstirrat15 tstirrat15 deleted the fix-csp-for-search-bar branch December 8, 2025 01:41
@tstirrat15
Copy link
Collaborator Author

Merging to test in live.

@github-actions github-actions bot locked and limited conversation to collaborators Dec 8, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants