Skip to content

Conversation

@tstirrat15
Copy link
Collaborator

@tstirrat15 tstirrat15 commented Dec 8, 2025

Description

Loading the script 'https://docs-authzed.vercel.app/docs/_next/static/chunks/b542f544-ea2bdd057dfb27cd.js' violates the following Content Security Policy directive: "default-src 'self' authzed.com 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback. The action has been blocked.

I'm not sure why this doesn't fall under 'self'. I'm guessing this is some vercel weirdness. I wish they had this documented somewhere.

I'm trying the approach of adding both domains to both CSPs.

Changes

  • Add both domains to both CSPs.

Testing

Review.

@vercel
Copy link
Contributor

vercel bot commented Dec 8, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
docs Building Building Preview Comment Dec 8, 2025 3:37am

@tstirrat15 tstirrat15 merged commit 9b68b9b into main Dec 8, 2025
7 of 8 checks passed
@tstirrat15 tstirrat15 deleted the make-csps-match branch December 8, 2025 03:38
@github-actions github-actions bot locked and limited conversation to collaborators Dec 8, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants