# External nginx pagespeed module causes Security Policy violation

**URL:** https://meta.discourse.org/t/external-nginx-pagespeed-module-causes-security-policy-violation/121336
**Category:** Self-hosting
**Created:** [June 25, 2019, 11:59pm UTC](https://meta.discourse.org/t/external-nginx-pagespeed-module-causes-security-policy-violation/121336 "2019-06-25T23:59:38Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![34563463456](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/34563463456/32/141024_2.png) [@34563463456](https://meta.discourse.org/u/34563463456)
#### Post date: [June 26, 2019, 5:53pm UTC](https://meta.discourse.org/t/external-nginx-pagespeed-module-causes-security-policy-violation/121336/6 "2019-06-26T17:53:40Z")

</div>

@pfaffman: yes it works with https without the orange cloud. So, the first time I set it up, it worked out of the box and since I did not use the cloudflare template I had no CSP issues.

I just saw a [post](https://meta.discourse.org/t/full-site-cdn-acceleration-for-discourse/21467/10) which mentioned: `DISCORSE_ENABLE_CORS: true` should be set. I havent tried it yet however (will try in few mins)

BTW: I have an nginx front end with https (letsencrypt) serving a reverse proxy discourse instance. Thus I had commented out `templates/web.ssl.template.yml` - do you think should include this now that I have the cloudflare template on?

---

_[View the full topic](https://meta.discourse.org/t/external-nginx-pagespeed-module-causes-security-policy-violation/121336)._
