Magento2 CSP frame-ancestors配置后googleapis资源仍被拦截问题
Magento 2 CSP配置错误原因及解决方案
核心错误:指令用途匹配错误
frame-ancestors 是CSP中用于指定哪些外部站点可以将你的Magento站点嵌入到iframe/frame等容器中的指令,和「允许站点加载外部JS资源」的需求完全无关。你要放行的谷歌翻译JS属于外部脚本资源,应该配置到script-src或script-src-elem指令下,而非frame-ancestors,这是配置不生效的核心原因。
报错根因说明
你收到的The Content-Security-Policy directive 'frame-ancestors' does not support the source expression 'unsafe-inline'报错,是因为frame-ancestors本身不支持unsafe-inline、unsafe-eval这类源值,可排查两个方向:
- 你的自定义CSP扩展中是否错误给
frame-ancestors添加了unsafe-inline配置 - 是否有其他第三方扩展自动注入了无效的
frame-ancestors参数
正确配置示例
要放行translate.googleapis.com的JS资源,按你的配置格式修改为如下内容即可:
<policy id="script-src"> <values> <value id="google-apis" type="host">*.googleapis.com</value> </values> </policy>
如果同时需要放行该域名下的样式资源,同步添加到style-src指令即可。
内容的提问来源于stack exchange,提问作者Eric Brown
相关产品推荐
相关产品推荐

