已设置CSP仍违反内容安全策略?VITE+Matomo连接问题求助
解决Vite中Matomo连接违反CSP的问题
问题分析
你的报错源于CSP的connect-src规则解析异常——尽管你添加了https://myapp.matomo.cloud/*,但配置里的冗余内容导致这条规则未被正确识别:
- connect-src中混入了属于
script-src的脚本URL(https://cdn.matomo.cloud/myapp.matomo.cloud/container_XXX.js),这不属于连接目标范畴,会干扰CSP的规则解析 - 重复多次声明
blob:,属于语法冗余,可能导致后续源规则被忽略 https://myapp.matomo.cloud/*的写法本身没问题,但前面的语法错误让这条规则无法生效
修正后的CSP配置
VITE_APP_CSP_POLICY="default-src 'self'; img-src 'self' data:; manifest-src 'self'; style-src 'self' fonts.googleapis.com 'unsafe-inline'; font-src 'self' data: fonts.gstatic.com; script-src 'self' 'unsafe-eval' https://www.data-dog-url.com https://cdn.matomo.cloud/myapp.matomo.cloud/container_XXX.js https://myapp.matomo.cloud; connect-src 'self' blob: somesite.eu https://myapp.matomo.cloud https://*.amazonaws.com;"
关键修改点
- 移除connect-src中的
https://cdn.matomo.cloud/myapp.matomo.cloud/container_XXX.js,该URL仅需保留在script-src中 - 合并重复的
blob:声明,仅保留一次即可覆盖所有blob类型的连接请求 - 将
connect-src里的https://myapp.matomo.cloud/*简化为https://myapp.matomo.cloud(CSP中指定域名即可匹配该域名下所有路径、带查询参数的请求,*在这里属于冗余写法)
修改后,Matomo的https://myapp.matomo.cloud/matomo.php?xxx请求就能正确匹配connect-src规则,不会再触发CSP报错。
内容的提问来源于stack exchange,提问作者Whichmann
相关产品推荐
相关产品推荐

