olivier olivier - 6 months ago 57
Android Question

http-equiv Content-Security-Policy works in browser but not on android device - IONIC

I'm developing an app with ionic and just inserted this Content-Security-Policy meta-tag.

<meta http-equiv="Content-Security-Policy" content="default-src *; style-src 'self' fonts.googleapis.com 'unsafe-inline'; script-src 'self' code.jquery.com cdn.firebase.com www.gstatic.com maps.googleapis.com localhost:35729 apis.google.com 'unsafe-inline' 'unsafe-eval' https://domain.com">

I don't get any errors in the browser but alot on the android device.
I'm using crosswalk.

No errors in chrome locally but when i inspect the app with chrome://inspect and run it on the device I get these errors:

So the Content-Security-Policy isn't working on the device at all.

enter image description here

What's my mistake?


It appears you need an explicit URI scheme as described here:

   content security policy error, but meta-tag includes URL

Thus, something like this should work:

<meta http-equiv="Content-Security-Policy" content="default-src *; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; script-src 'self' https://code.jquery.com https://cdn.firebase.com  https://www.gstatic.com https://maps.googleapis.com localhost:35729 https://apis.google.com 'unsafe-inline' 'unsafe-eval' https://domain.com">