在我们的项目中,我们已经配置并传入了CSP Response Headers.此外,我们有简单的Service Worker,它检查是否可以导航到另一个页面,如果没有重定向到缓存的离线html页面.这是fetch事件的Service Worker的一部分代码
self.addEventListener('fetch', function (event) {
event.respondWith(
// Try to find requested resource in the cache
caches
.match(event.request).then(function (response) {
// Fallback to network if it's not in cache
return response || fetch(event.request);
})
.catch(getFallbackResponse(event))
);
});
Run Code Online (Sandbox Code Playgroud)
但是,当CSP配置发生变化并且在CSP配置中发生此更改之前安装了Service Worker时,我们会收到
Refused to load the script '[url]' because it violates the following Content Security Policy directive: ...错误.一旦我们更新或取消注册Service Worker,就会应用新的CSP配置.
这是预期的行为吗?