Inclushe / figma-ui3

Enable UI3 Beta for Figma
MIT License
17 stars 2 forks source link

CSP issue #1

Open Inclushe opened 2 months ago

Inclushe commented 2 months ago

Is there an issue in Russia only?

Den Borisov gave you 1 star and said: "Refused to load the script 'chrome-extension://gdjldebhilhckhblmhklofdebemiahhi/src/format.js' because it violates the following Content Security Policy directive: "script-src 'self' https://www.figma.com/ 'unsafe-eval' 'unsafe-inline' https://admin.figma.com/admin/webpack-artifacts/ https://figma-private-data.s3.us-west-2.amazonaws.com/webpack-artifacts/ blob: https://accounts.google.com/gsi/client https://static.figma.com/fullscreen/ https://static.figma.com/uploads/539fd13ba437049b058e7e83fd54539c86878320 https://static.figma.com/uploads/0706b46bdc09a419282285b791ea1dd3c019ecd6 https://static.figma.com/scripts/ https://static.zdassets.com https://ekr.zdassets.com https://assets.zendesk.com/apps/sdk/2.0/zaf_sdk.js https://js.stripe.com https://trello.com/power-ups/power-up.min.js https://p.trellocdn.com/power-up.min.js https://statics.teams.cdn.office.net/sdk/v1.6.0/js/MicrosoftTeams.min.js https://alcdn.msauth.net/browser/2.21.0/js/msal-browser.min.js https://apis.google.com/". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback."

Inclushe commented 1 month ago

"It seems unable to work in certain situations in Chrome, tip"because it violates the following Content Security Policy directive: "script-src 'self""