# \#content-security-policy

**URL:** https://meta.discourse.org/tag/content-security-policy/646.md

[Latest](https://meta.discourse.org/latest.md) · [Categories](https://meta.discourse.org/categories.md) · [Tags](https://meta.discourse.org/tags.md)

---

## [Refused to load the script 'site.com/cdn-cgi/speculation' because it violates the following Content Security Policy directive](https://meta.discourse.org/t/refused-to-load-the-script-site-com-cdn-cgi-speculation-because-it-violates-the-following-content-security-policy-directive/327466)

<div class="topic-metadata">

**Author:** [@kuaza](https://meta.discourse.org/u/kuaza)\
**Replies:** 3\
**Last updated:** [September 22, 2024, 1:01am UTC](https://meta.discourse.org/t/refused-to-load-the-script-site-com-cdn-cgi-speculation-because-it-violates-the-following-content-security-policy-directive/327466 "2024-09-22T01:01:41Z")

</div>

I looked at the console.log and saw these errors. Why could it be? Google Analytics does not see the AdSense user approval feature. That’s why I noticed it when I looked at the console area. What do you think could be th…

---

## [CSP error when adding a script via a theme component](https://meta.discourse.org/t/csp-error-when-adding-a-script-via-a-theme-component/324482)

<div class="topic-metadata">

**Author:** [@devops1](https://meta.discourse.org/u/devops1)\
**Replies:** 8\
**Last updated:** [September 5, 2024, 4:55pm UTC](https://meta.discourse.org/t/csp-error-when-adding-a-script-via-a-theme-component/324482 "2024-09-05T16:55:44Z")

</div>

Issue with Strict Dynamic and CSP on Atlassian Widget I am encountering an issue with Content Security Policy (CSP) after updating to v3.3.0.beta1. Specifically, I’m trying to embed an Atlassian widget in the header of m…

---

## [Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243)

<div class="topic-metadata">

**Author:** [@Discourse](https://meta.discourse.org/u/Discourse)\
**Replies:** 30\
**Last updated:** [June 13, 2023, 10:50pm UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243 "2023-06-13T22:50:33Z")

</div>

:bookmark: This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. :person\_raising\_hand: Requir…
