Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Lolu chungechunge lwabekwa kunqolobane. Uyacelwa ubuze umbuzo omusha uma udinga usizo.

Site not loading when using ESR due to CSP

  • 4 uphendule
  • 0 zinale nkinga
  • 2 views
  • Igcine ukuphendulwa ngu chris.foster1

more options

One of our vendors websites does not load under Firefox ESR, with errors in the console pointing to CSP. Error is: Content Security Policy: The page's settings blocked the loading of a resource at inline ("default-src")

However if I load the site under the normal Firefox release, it displays correctly. When looking at errors in console, it is showing 3 errors for CSP, however it does not stop the site from working correctly. Content-Security-Policy: The page's settings blocked the loading of a resources at https://..... ("connect-src") or ("img-src")

The site is https://app.approvalmax.com If you get the login screen then the site is working otherwise just getting a green background when it is not working.

I am unsure why ESR and RR versions are behaving differently in this case. Using the latest versions of each.

One of our vendors websites does not load under Firefox ESR, with errors in the console pointing to CSP. Error is: Content Security Policy: The page's settings blocked the loading of a resource at inline ("default-src") However if I load the site under the normal Firefox release, it displays correctly. When looking at errors in console, it is showing 3 errors for CSP, however it does not stop the site from working correctly. Content-Security-Policy: The page's settings blocked the loading of a resources at https://..... ("connect-src") or ("img-src") The site is https://app.approvalmax.com If you get the login screen then the site is working otherwise just getting a green background when it is not working. I am unsure why ESR and RR versions are behaving differently in this case. Using the latest versions of each.

Okulungisiwe ngu chris.foster1

Isisombululo esikhethiwe

This was fixed by https://bugzilla.mozilla.org/show_bug.cgi?id=1640128 in Firefox 109.

which unfortunately was not backported to the Firefox 102 ESR.

It works in the Firefox 115 ESR which will become the only supported ESR in a month.

I'm checking to see if there is a workaround.

Funda le mpendulo ngokuhambisana nalesi sihloko 👍 1

All Replies (4)

more options

Which ESR?

more options

Firefox ESR 102.14.0 I have also tested with older releases of ESR (which are deployed within the organisation) and they are doing the same result.

more options

Isisombululo Esikhethiwe

This was fixed by https://bugzilla.mozilla.org/show_bug.cgi?id=1640128 in Firefox 109.

which unfortunately was not backported to the Firefox 102 ESR.

It works in the Firefox 115 ESR which will become the only supported ESR in a month.

I'm checking to see if there is a workaround.

more options

Thanks Mike. I have now tested using Firefox 115 ESR in my test VM and confirm that it does work. I'll need to get our team to look at pushing/deploying this through our organisation.