Fork me on GitHub

What’s the correct way of dealing with…

Refused to load the script '' because it violates the following Content Security Policy directive: "script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:". 'strict-dynamic' is present, so host-based whitelisting is disabled.
…? ClojureScript seems to make Chrome go into pouty mode.


I assume it’s something to do with all the document.writes in app.js.


@nxqd cheers, that actually did it! Though turning it off seems like cheating. Either cljs is compiling into insecure js, or there’s something wonky with how Pedestal is serving the file.


cljs compiles insecure js in normal mode, it shouldn't have any problem with advanced compiled. You can do a little research about secure header, the default one is too strict in my opinion.


Either way, it seems like the Leiningen template could do with an update to fix this for dev mode.


yeah, true