CSP violation 🟨 JavaScript

Refused to load the script because it violates the following Content Security Policy directive

The page’s Content-Security-Policy doesn’t allow that script, style, image or connection source.

Seen on: JavaScript

Meaning

CSP headers whitelist sources. New third-party scripts (analytics, ads, fonts), inline scripts or eval are blocked until added to the policy.

Common causes

  • Third-party domain not in script-src/connect-src
  • Inline script without nonce/hash
  • eval/new Function blocked by missing unsafe-eval
  • Images/fonts from unlisted domains

⚡ Quick fix

  1. Add the domain to the right directive
  2. Use nonces/hashes for inline scripts
  3. Test with Content-Security-Policy-Report-Only first

Detailed fix by platform

Nginx

  1. add_header Content-Security-Policy "script-src 'self' https://www.googletagmanager.com" always;

How to diagnose

  1. Directive — Which directive is violated?
  2. Source — Which URL was blocked?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.