You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生产服务器上Laravel Livewire与CSP内容安全策略兼容问题

Laravel Livewire 3.4 生产环境下的CSP(内容安全策略)问题

环境配置

开发环境

  • 操作系统:Laragon本地开发环境
  • Web服务器:Nginx
  • Laravel版本:10
  • Livewire版本:3.4
  • NPM版本:9.8.1
  • Node.js版本:18.18.2
  • Vite版本:3.0.2
  • 测试浏览器:Chrome

生产环境

  • 操作系统:Ubuntu 20.04.6 LTS
  • Web服务器:Nginx v1.18.0
  • Laravel版本:10
  • Livewire版本:3.4
  • NPM版本:10.7.0
  • Node.js版本:20.13.1
  • Vite版本:3.2.10
  • 测试浏览器:Chrome

问题详情

生产环境访问应用时,出现与Livewire JavaScript文件相关的错误:

警告信息:

Alpine Expression Error: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'".

Expression: "tableWrapper($wire, )"

错误信息:

Uncaught EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'".

at new AsyncFunction (<anonymous>)
at safeAsyncFunction (livewire.js?id=239a5c52:1254:21)
at generateFunctionFromString (livewire.js?id=239a5c52:1264:16)
at generateEvaluatorFromString (livewire.js?id=239a5c52:1269:16)
at normalEvaluator (livewire.js?id=239a5c52:1234:111)
at evaluateLater (livewire.js?id=239a5c52:1224:12)
at evaluate (livewire.js?id=239a5c52:1220:5)
at Function.<anonymous> (livewire.js?id=239a5c52:3491:17)
at flushHandlers (livewire.js?id=239a5c52:1358:48)
at stopDeferring (livewire.js?id=239a5c52:1363:7)

Nginx配置

生产服务器的Nginx配置如下:

server {
listen 443 ssl http2;
server_name system.example.com;
set $base /app/system;
root $base/public;

add_header Content-Security-Policy "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'";

include nginxconfig.io/ssl.conf;
include nginxconfig.io/security.conf;

access_log /var/log/nginx/system-access.log combined buffer=512k flush=1m;
error_log /var/log/nginx/system-error.log warn;

index index.php;

location / {
    try_files $uri $uri/ /index.php?$query_string;
}

include nginxconfig.io/general.conf;

location ~ \.php$ {
    fastcgi_pass unix:/var/run/php/php-fpm.sock;
    include nginxconfig.io/php_fastcgi.conf;
}

location = /livewire/livewire.js {
    expires off;
    try_files $uri $uri/ /index.php?$query_string;
}
}

server {
    listen 80;
    server_name system.example.com;

    location / {
        return 301 https://system.example.com$request_uri;
    }
}

已尝试方案

  1. 在CSP头中添加'unsafe-eval':
add_header Content-Security-Policy "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline' 'unsafe-eval'";
  1. 验证服务器上已存在所需文件。

以上方案均未解决问题,恳请指导如何正确配置Livewire以适配严格的CSP,或提供无需使用'unsafe-eval'的替代方案。


内容的提问来源于stack exchange,提问作者Faizal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 23:30:12