-
Notifications
You must be signed in to change notification settings - Fork 157
Closed
Description
I have no Content Security Policy and am getting this error when opening the component:
Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self' 'unsafe-eval' https://*.plaid.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.getpinwheel.com/ https://maps.googleapis.com/ 'sha256-0dB7snFz1Yn71aHVRfAoFCKDCBcB9Z53FLbPddsZzdc=' 'sha256-Q2BuusfJf7qPwvz9U1VOF502KW7JtNFXxsDsxfPIu50='”. Consider using a hash ('sha256-IqGY6QBgGV+ingxiP5yKtj7yFX6kZyNwwpAPE6Kq28w=') together with 'unsafe-hashes'.
Does the iframe have its own CSP that is failing?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels