# Content Security Policy fails

**URL:** <https://discourse.nodered.org/t/content-security-policy-fails/31694>\
**Category:** Dashboard\
**Created:** [18 August 2020 14:44 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694 "2020-08-18T14:44:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [18 August 2020 14:44 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/1 "2020-08-18T14:44:44Z")

</div>

Just coming back to Node-RED after a long absence, and I find that either my Node-RED server (v0.20.5) no longer sets the correct Content Security Policy header, my browser no longer recognises it (Firefox 68.11.0esr), or something else related to CSP is borked; my dashboard won't load (I just get a blank page) and the browser console reports `Content Security Policy: The page’s settings blocked the loading of a resource at https://192.168.11.12:1880/ui/js/app.min.js (“script-src”).` I've tried `npm update` etc, but no change. Tired and confused after returning home from four months of Covid-19 induced exile, what am I missing?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 August 2020 15:01 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/2 "2020-08-18T15:01:51Z")

</div>

Do you normally use https access rather than http even on the local network?

---

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [18 August 2020 15:08 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/3 "2020-08-18T15:08:09Z")

</div>

Yes. IIRC [HSTS](https://en.wikipedia.org/wiki/HSTS) is enabled. The admin interface works fine.

---

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [20 August 2020 18:45 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/4 "2020-08-20T18:45:39Z")

</div>

_\>bump\<_

Anyone?

---

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [21 August 2020 15:44 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/5 "2020-08-21T15:44:05Z")

</div>

I have upgraded my node-red box from Jessie to Buster (via Stretch), node.js to 12.18.3, node-red to 1.1.3 and node-red-dashboard to 2.23.2. The problem remains the same. Extensive searching on the interwebs has come up with nothing.

The issue appears to be related to NoScript:

 ![Screenshot_2020-08-21_16-43-59](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/1/d1c0d5eeb6291fa338617cee60b0d1c25f81d3dc.png)

---

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [21 August 2020 16:30 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/6 "2020-08-21T16:30:59Z")

</div>

Curisouly, NoScript still intercepts the CSP reports even after _uninstalling_ NoScript completely and restarting Firefox:

```auto
  POST noscript-csp.invalid / __NoScript_Probe__ / csp 0 B 0 B 1 ms
  POST noscript-csp.invalid / __NoScript_Probe__ / csp 0 B 0 B 1 ms
  POST noscript-csp.invalid / __NoScript_Probe__ / csp 0 B 0 B 1 ms

```

I don't think this is the issue though; the CSP reports are generated because loading of the node-red-dashboard scripts fails the CSP check - the fact that NoScript intercepts the reports has nothing to do with the scripts failing the check; it happens because the report URL is invalid (or in this case `null`). So I'm still nowhere closer to being able to access the node-red-dashboard which worked perfectly six months ago.

---

<div class="post-metadata">

**Author:** ![clickworkorange](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/clickworkorange/32/12109_2.png) [@clickworkorange](https://discourse.nodered.org/u/clickworkorange)\
**Post date:** [21 August 2020 16:38 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/7 "2020-08-21T16:38:49Z")

</div>

LOL. Fixed! By clearing cookies & data for 192.168.13.100 and logging back in. Go figure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [4 September 2020 16:38 UTC](https://discourse.nodered.org/t/content-security-policy-fails/31694/8 "2020-09-04T16:38:50Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
