Skip to content

Commit 5677a65

Browse files
Fix CSP for Firebase auth
The AI identified that the login issue on Vercel was caused by Content Security Policy (CSP) violations preventing Firebase authentication requests. It updated `index.html` to include the necessary Firebase domains in the `connect-src` directive. The AI instructed the user to redeploy the Vercel application after this change.
1 parent 231e3ee commit 5677a65

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

vercel.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@
3232
},
3333
{
3434
"key": "Content-Security-Policy",
35-
"value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.gpteng.co https://embed.tawk.to https://va.tawk.to; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://api.stripe.com https://refspring-default-rtdb.europe-west1.firebasedatabase.app wss://embed.tawk.to; frame-src https://js.stripe.com https://embed.tawk.to; object-src 'none'; base-uri 'self'; upgrade-insecure-requests"
35+
"value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.gpteng.co https://embed.tawk.to https://va.tawk.to; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://api.stripe.com https://refspring-default-rtdb.europe-west1.firebasedatabase.app https://identitytoolkit.googleapis.com https://securetoken.googleapis.com https://firestore.googleapis.com https://us-central1-refspring-8c3ac.cloudfunctions.net wss://embed.tawk.to; frame-src https://js.stripe.com https://embed.tawk.to; object-src 'none'; base-uri 'self'; upgrade-insecure-requests"
3636
}
3737
]
3838
}

0 commit comments

Comments
 (0)