CSS fails, if default-src "self" configured

Created on 11 May 2025, 5 days ago

I tried to use this module and found a problem. If I activate "Send HTTP response header" and write "self" into the default-src field the site fails to display CSS right.

🐛 Bug report
Status

Active

Version

2.0

Component

Code

Created by

🇩🇪Germany drupalbubb

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

  • Issue created by @drupalbubb
  • 🇩🇪Germany drupalbubb

    Ok, this is a experience report, but no bug report. And a feature request.

    - Please add some more input validation to all directives for CSP. Or add checkboxes or a dropdown list with valid selections. I forgot the quotes from 'self' as example.
    - Maybe some predefined profiles make sense.
    - Consider renaming some config values, e.g. "checkbox" (yes, drush saved my day)

Production build 0.71.5 2024