lisonge / vite-plugin-monkey

A vite plugin server and build your.user.js for userscript engine like Tampermonkey, Violentmonkey, Greasemonkey, ScriptCat
MIT License
1.39k stars 71 forks source link

搞定设计 网站 CSP 如何绕过? #175

Closed long36708 closed 3 months ago

long36708 commented 3 months ago

控制台报错如下: server:vite-monkey-project.user.js:60 Refused to load the script 'http://127.0.0.1:5173/__vite-plugin-monkey.entry.js' because it violates the following Content Security Policy directive: "script-src 'self' at.alicdn.com 'unsafe-eval' 'unsafe-inline' data: blob: .dancf.com .gaoding.com .gaoding.cn .focodesign.com .insmind.com .wx.qq.com hm.baidu.com tongji.baidu.com assetscli.udesk.cn ttxsapp.udesk.cn retcode.alicdn.com www.google-analytics.com www.googletagmanager.com https://quickapp/jssdk.webview.min.js https://apis.google.com https://g.alicdn.com .aliapp.org .alibaba.com .aliyun.com https://webapi.amap.com .amap.com *.smartlook.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

lisonge commented 3 months ago

https://github.com/lisonge/vite-plugin-monkey?tab=readme-ov-file#csp