setings.py:
CSP_DEFAULT_SRC = ("'self'",)
CSP_INCLUDE_NONCE_IN = ('script-src', )
CSP_STYLE_SRC = ("'self'",
"rbsA2VBKQhggwzxH7pPCaAqO46MgnOM80zW1RWuH61DGLwZJEdK2Kadq2F9CUG65",
"https://cdn.jsdelivr.net/npm/[email protected]/dist/css/bootstrap.min.css",)
CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'",
"https://cdn.jsdelivr.net/npm/[email protected]/dist/js/bootstrap.bundle.min.js")
html:
<link rel="stylesheet"
href="https://cdn.jsdelivr.net/npm/[email protected]/dist/css/bootstrap.min.css"
integrity="sha384-rbsA2VBKQhggwzxH7pPCaAqO46MgnOM80zW1RWuH61DGLwZJEdK2Kadq2F9CUG65" crossorigin="anonymous">
<link rel="stylesheet"
href="https://cdnjs.cloudflare.com/ajax/libs/bootstrap-icons/1.10.2/font/bootstrap-icons.min.css"
integrity="sha512-YFENbnqHbCRmJt5d+9lHimyEMt8LKSNTMLSaHjvsclnZGICeY/0KYEeiHwD1Ux4Tcao0h60tdcMv+0GljvWyHg=="
crossorigin="anonymous">
Browser Console: Content-Security-Policy: The page’s settings blocked the loading of a resource at https://cdnjs.cloudflare.com/ajax/libs/bootstrap-icons/1.10.2/font/bootstrap-icons.min.css (“style-src”).
I have already tried to add them to CSP_STYLE_SRC, CSP_IMG_SRC and to CSP_DEFAULT_SRC. What am i missing?