Skip to content

Stashbox CORS update #3

@Splash4K

Description

@Splash4K

Stashbox and stashdb updated to have stricter CORS policy so now there are errors with the userscript when it comes to loading content: (icons, css etc)

Refused to apply inline style because it violates the following Content Security Policy directive: "style-src 'self' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='". Either the 'unsafe-inline' keyword, a hash ('sha256-hAe53L/Tp4DHv5ftMb00LEuBCFxDkF/zA+1UijNXxoI='), or a nonce ('nonce-...') is required to enable inline execution.

Refused to load the image 'data:image/svg+xml,%3csvg xmlns='http://www.w3.org/2000/svg' viewBox='-4 -4 8 8'%3e%3ccircle r='3' fill='rgba%280, 0, 0, 0.25%29'/%3e%3c/svg%3e' because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

Also, the settings panel in the top right is now being shown by default, which I'm guessing may be related to the CSS being blocked.

Pic for reference:
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions