cfpb / hmda-frontend

Collection of HMDA frontend apps
Creative Commons Zero v1.0 Universal
12 stars 15 forks source link

CSP Blocking dap.digitalgov.gov #2192

Closed ojbravo closed 3 months ago

ojbravo commented 4 months ago

The following error is showing in the browser console: Refused to load the script 'https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=CFPB' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' blob: data: https://tagmanager.google.com https://www.googletagmanager.com https://www.google-analytics.com https://*.cfpb.gov https://www.consumerfinance.gov https://cdn.mouseflow.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.