Search code examples

Content Security Policy not allowing execution of script even though domain is listed in script-src

I'm attempting to help one of our QA engineers be able to run a script on the console in our dev environment.

The script-src portion of the CSP is as follows:

script-src 'unsafe-inline' 'self' * * *;

However, when executing their script, I receive this error:

[Report Only] Refused to load the script '' because it violates
the following Content Security Policy directive: "script-src 'unsafe-inline' 'self' *
* *". Note that 'script-src-elem' was not explicitly set, so 'script-src'
is used as a fallback.

Shouldn't * in the Content Security Policy cover this scenario? What am I missing here?


  • No. * allows all subdomains of, but not itself. You will need to add to script-src.