拒绝加载字体,因为它违反了以下内容安全策略指令:“ default-src'none'”

时间:2019-11-25 07:47:07

标签: html express

我使用express的原因是我有好几页并托管,所有其他页面一直在服务器中加载,但是当我单击一页(/ newscategories / Bitcoin_news / 1)时,它会显示

无法获取错误,并且在控制台中显示:

1:1拒绝加载字体“ https://fonts.gstatic.com/s/opensans/v13/DXI1ORHCpsQm3Vp6mXoaTegdm0LZdjqr5-oayXSOefg.woff2”,因为它违反了以下内容安全策略指令:“ default-src'none'”。请注意,未明确设置“ font-src”,因此将“ default-src”用作备用。

1:1拒绝加载图像'https://beingevent.com/favicon.ico',因为它违反了以下内容安全策略指令:“ default-src'none'”。请注意,未明确设置“ img-src”,因此将“ default-src”用作备用。

在app.js中

app.engine('.html', require('ejs').__express);
app.use(express.static(__dirname + '/public'));

bodyParser = require('body-parser');
app.use(bodyParser.urlencoded({ extended: false }))
app.use(bodyParser.json())
app.set('view engine', 'html');
app.set('views', __dirname + '/views');

该页面的HTML代码

<!DOCTYPE html>
<html>
<head>
    <title>Crypto-News</title>
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-147461007-1"></script>
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag('js', new Date());

  gtag('config', 'UA-147461007-1');
</script>
    <meta charset="UTF-8">
    <!-- <meta http-equiv="Content-Security-Policy" content="default-src *; style-src * 'unsafe-inline'; script-src * 'unsafe-inline' 'unsafe-eval'; img-src * data: 'unsafe-inline'; connect-src * 'unsafe-inline'; frame-src *;"> -->
    <!-- <meta http-equiv="content_security_policy": "default-src 'self' style-src 'self' 'unsafe-inline';" > -->
    <!-- <meta http-equiv="Content-Security-Policy" content="default-src 'self' https://fonts.googleapis.com https://beingevent.s3.ap-south-1.amazonaws.com https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css; connect-src * 'unsafe-inline';"> -->
    <!-- <meta http-equiv="Content-Security-Policy" content="default-src 'self'; font-src 'self'  https://fonts.googleapis.com;"> -->
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <meta name="mobile-web-app-capable" content="yes">
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <meta name="keywords" content="We do premier events to help connect like-minded entrepreneurs, industry insiders, investors." />
    <link href="https://fonts.googleapis.com/css?family=Montserrat|Open+Sans|Open+Sans+Condensed:300|Roboto&display=swap" rel="stylesheet">
    <link href="https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css" rel="stylesheet">
    <link rel="stylesheet" type="text/css" href="/css/style.css">
    <link rel="stylesheet" href="/css/owl-1.css">
    <link rel="stylesheet" href="/css/owl-2.css">
    <link href="/css/bootstrap.css" rel="stylesheet">
    <link href="/css/bootstrap.min.css" rel="stylesheet">
    <link rel="stylesheet" type="text/css" href="/css/boot.css">
    <script type="text/javascript" src="/jss/qr/jquery.min.js"></script>
    <script type="text/javascript" src="/jss/qr/qrcode.js"></script>
    <script src="https://unpkg.com/sweetalert/dist/sweetalert.min.js"></script>
    <script async src="https://www.googletagmanager.com/gtag/js?id=UA-150412361-1"></script>
    <script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.2.1/jquery.min.js"></script>
    <script src="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.js"></script>
    <script src="https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.2.1/owl.carousel.min.js">
    <script src="/js/main.js"></script>
    <script src="/jss/jquery.js"></script>
 <script src="/jss/list-builder.js"></script>
 <script src="/jss/move/util.js"></script>
 <script src="/jss/move/main.js"></script>

在本地运行良好,没有错误,但是在服务器中没有运行show error我找不到解决方案,请帮帮我

0 个答案:

没有答案