Hi I'm trying to serve a static js using
::http/resource-path "public"
in the service map but I get an csp error Refused to load the script '<https://xxx/stats/stats.js>' because it violates the following Content Security Policy directive: "script-src self". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
.Any tips 🙂
It seems to me you have to configure CSP for your use case
Tnx yes I managed to solve it by adding
::http/secure-headers {:content-security-policy-settings {:script-src "https://*.<http://olle.com:*%22|olle.com:*">}}
to my service map.