小编yar*_*arm的帖子

服务工作者和CSP配置更改

在我们的项目中,我们已经配置并传入了CSP Response Headers.此外,我们有简单的Service Worker,它检查是否可以导航到另一个页面,如果没有重定向到缓存的离线html页面.这是fetch事件的Service Worker的一部分代码

self.addEventListener('fetch', function (event) {
  event.respondWith(
    // Try to find requested resource in the cache
    caches
      .match(event.request).then(function (response) {
        // Fallback to network if it's not in cache
        return response || fetch(event.request);
      })
      .catch(getFallbackResponse(event))
    );
});
Run Code Online (Sandbox Code Playgroud)

但是,当CSP配置发生变化并且在CSP配置中发生此更改之前安装了Service Worker时,我们会收到 Refused to load the script '[url]' because it violates the following Content Security Policy directive: ...错误.一旦我们更新或取消注册Service Worker,就会应用新的CSP配置.

这是预期的行为吗?

content-security-policy service-worker

8
推荐指数
1
解决办法
424
查看次数