E
E
evilelf2015-11-17 12:00:29
PHP
evilelf, 2015-11-17 12:00:29

How to fix the problem?

Refused to connect to ' http://site.ru' because it violates the following Content Security Policy directive: "default-src 'self' data: gap: https://ssl.gstatic.com 'unsafe-eval'". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.

With iframe and jquery ajax.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
E
evilelf, 2015-11-17
@evilelf

problem solved

header("Access-Control-Allow-Origin: *");
header("Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT");
header("Access-Control-Max-Age: 0");
header("Content-Security-Policy: default-src *; connect-src *; script-src *; object-src *;");
header("X-Content-Security-Policy: default-src *; connect-src *; script-src *; object-src *;");
header("X-Webkit-CSP: default-src *; connect-src *; script-src 'unsafe-inline' 'unsafe-eval' *; object-src *;");

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question