无法识别的Content-Security-Policy指令'reflected-xss'

时间:2018-06-25 08:07:55

标签: javascript css angular content-security-policy

我试图将我的角度项目上传到域中,但这是结果:许多错误和空白页。该应用程序可在其他域中运行,这是什么问题?

Unrecognized Content-Security-Policy directive 'reflected-xss'.

Unrecognized Content-Security-Policy directive 'referrer'.

aujLCz0nXqYKX_1BwLrsPu7JgCU.js:34 Refused to load the stylesheet 'data:text/css;charset=utf-8;base64,Y2xvdWRmbGFyZS1hcHBbYXBwPSJjZi1hdXRoLWJhciJdIHsKICBkaXNwbGF5OiBibG9jazsKICBkaXNwbGF5OiAtd2Via2l0LWJveDsKICBkaXNwbGF5OiAtbXMtZmxleGJveDsKICBkaXNwbGF5OiBmbGV4OwogIGZvbnQtd2VpZ2h0OiA3MDA7CiAgbGV0dGVyLXNwYWNpbmc6IC4wOGVtOwogIHBvaW50ZXItZXZlbnRzOiBub25lOwogIHRleHQtdHJhbnNmb3JtOiB1cHBlcmNhc2U7CiAgd2hpdGUtc3BhY2U6IG5vd3JhcDsKICBwb3NpdGlvbjogZml4ZWQ7CiAgdG9wOiAwOwogIGxlZnQ6IDA7CiAgcmlnaHQ6IDA7Cn0KCmNsb3VkZmxhcmUtYXBwW2FwcD0iY2YtYXV0aC1iYXIiXVtkYXRhLWhvcml6b250YWwtYWxpZ249ImxlZnQi...JvdyB3cmFwOwogICAgICAgICAgICBmbGV4LWZsb3c6IHJvdyB3cmFwOwogIH0KCiAgY2xvdWRmbGFyZS1hcHBbYXBwPSJjZi1hdXRoLWJhciJdIGNmLWFjdGlvbnMgewogICAgLXdlYmtpdC1ib3gtcGFjazogY2VudGVyOwogICAgICAgIC1tcy1mbGV4LXBhY2s6IGNlbnRlcjsKICAgICAgICAgICAganVzdGlmeS1jb250ZW50OiBjZW50ZXI7CiAgfQoKICBjbG91ZGZsYXJlLWFwcFthcHA9ImNmLWF1dGgtYmFyIl0gY2YtYWN0aW9ucyBhIHsKICAgIGRpc3BsYXk6IGJsb2NrOwogICAgLXdlYmtpdC1ib3gtZmxleDogMTsKICAgICAgICAtbXMtZmxleDogMSAwIGF1dG87CiAgICAgICAgICAgIGZsZXg6IDEgMCBhdXRvOwogICAgdGV4dC1hbGlnbjogY2VudGVyOwogIH0KfQoK' because it violates the following Content Security Policy directive: "default-src https://*". Note that 'style-src' was not explicitly set, so 'default-src' is used as a fallback.

(anonymous) @ aujLCz0nXqYKX_1BwLrsPu7JgCU.js:34
(anonymous) @ aujLCz0nXqYKX_1BwLrsPu7JgCU.js:34
addScript.js:9 Uncaught EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "default-src https://*".


    at eval (<anonymous>)
    at webpackJsonp../node_modules/script-loader/addScript.js.module.exports (addScript.js:9)
    at Object../node_modules/script-loader/index.js!./node_modules/moment/min/moment.min.js (moment.min.js?5a95:1)
    at __webpack_require__ (bootstrap 4a6340c19ac04ef00772:54)
    at Object.4 (scripts.bundle.js:79)
    at __webpack_require__ (bootstrap 4a6340c19ac04ef00772:54)
    at webpackJsonpCallback (bootstrap 4a6340c19ac04ef00772:25)
    at scripts.bundle.js:1

这只是错误的一部分。

0 个答案:

没有答案