"[仅报告]拒绝加载字体..."控制台上的错误消息

Gus*_*ira 20 javascript ember.js content-security-policy ember-cli

进一步来说:

[Report Only] Refused to load the font 'data:application/x-font-woff;charset=utf-8;base64,d09GRgABAAAAABBQAAoAAAAAG…H8zVsjnmMx0GcZ2HGViNOySWEa9fvEQtW43Nm+EOO0ZIpdLbMXoVzPJkcfHT6U+gLEpz/MAAAA' because it violates the following Content Security Policy directive: "font-src 'self'".
Run Code Online (Sandbox Code Playgroud)

这是我的contentSecurityPolicy目标environment.js:

contentSecurityPolicy: {
  'default-src': "'none'",
  'script-src': "'self' 'unsafe-inline' 'unsafe-eval' connect.facebook.net",
  'connect-src': "'self'",
  'img-src': "'self' www.facebook.com",
  'style-src': "'self' 'unsafe-inline'",
  'frame-src': "s-static.ak.facebook.com static.ak.facebook.com www.facebook.com",
  'report-uri': "http://localhost:4200"
},
Run Code Online (Sandbox Code Playgroud)

有什么不对的吗?

ore*_*ake 37

'font-src': "data:",正在加载的字体添加到白名单.

  • 我用''font-src':"'自我'数据:"`它工作正常,谢谢 (9认同)
  • `font-src'self'数据:https://fonts.gstatic.com https://fonts.googleapis.com/;`我修改了你的提示,现在它适用于我. (3认同)