Skip to content

Safari content security policy issues #52

@wschenk

Description

@wschenk
[Error] The Content Security Policy 'default-src 'none'; connect-src 'self' https://chatgpt.com https://sentinel.openai.com https://*.oaiusercontent.com https://api.openai.com https://browser-intake-datadoghq.com https://api-js.mixpanel.com; frame-src 'self' https://chatgpt.com https://sentinel.openai.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://chatgpt.com https://sentinel.openai.com; font-src https://cdn.openai.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:' was delivered in report-only mode, but does not specify a 'report-to'; the policy will have no effect. Please either add a 'report-to' directive, or deliver the policy via the 'Content-Security-Policy' header.
[Error] The Content Security Policy 'default-src 'none'; connect-src 'self' https://chatgpt.com https://sentinel.openai.com https://*.oaiusercontent.com https://api.openai.com https://browser-intake-datadoghq.com https://api-js.mixpanel.com; frame-src 'self' https://chatgpt.com https://sentinel.openai.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://chatgpt.com https://sentinel.openai.com; font-src https://cdn.openai.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:' was delivered in report-only mode, but does not specify a 'report-to'; the policy will have no effect. Please either add a 'report-to' directive, or deliver the policy via the 'Content-Security-Policy' header. (x3)
[Error] The Content Security Policy 'default-src 'none'; connect-src 'self' https://chatgpt.com https://sentinel.openai.com https://*.oaiusercontent.com https://api.openai.com https://browser-intake-datadoghq.com https://api-js.mixpanel.com; frame-src 'self' https://chatgpt.com https://sentinel.openai.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://chatgpt.com https://sentinel.openai.com; font-src https://cdn.openai.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:' was delivered in report-only mode, but does not specify a 'report-to'; the policy will have no effect. Please either add a 'report-to' directive, or deliver the policy via the 'Content-Security-Policy' header. (x3)
[Error] Permission policy 'Fullscreen' check failed for document with origin 'https://cdn.platform.openai.com'.
	(anonymous function) (main.js:1:4495)
	M (main.js:1:6680)
	l (main.js:1:8287)
	m (main.js:1:8365)
	(anonymous function) (main.js:1:5082)
	Global Code (main.js:1:10045)
[Error] The Content Security Policy 'default-src 'none'; connect-src 'self' https://chatgpt.com https://sentinel.openai.com https://*.oaiusercontent.com https://api.openai.com https://browser-intake-datadoghq.com https://api-js.mixpanel.com; frame-src 'self' https://chatgpt.com https://sentinel.openai.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://chatgpt.com https://sentinel.openai.com; font-src https://cdn.openai.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:' was delivered in report-only mode, but does not specify a 'report-to'; the policy will have no effect. Please either add a 'report-to' directive, or deliver the policy via the 'Content-Security-Policy' header.
[Error] Permission policy 'Fullscreen' check failed for document with origin 'https://sentinel.openai.com'.
	(anonymous function) (main.js:1:4458)
	M (main.js:1:5791)
	l (main.js:1:8088)
	m (main.js:1:8166)
	(anonymous function) (main.js:1:5051)
	Global Code (main.js:1:10011)

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions