.aspx?HCCID = 75694719&amp; culture = en-US&amp; mlcv = 3006&amp; template = 5:7拒绝加载图片’https://s4.mylivechat.com/livechat2/images/sprite.png',因为它违反了以下内容 安全 </跨度> 政策 </跨度> 指令:“img-src’自我’数据:”。 拒绝将表单数据发送到“https://cipg.stanbicibtcbank.com/MerchantServices/MakePayment.aspx”,因为它违反了以下内容 安全 </跨度> 政策 </跨度>
你正在通过 Content-Security-Policy 响应标头中的值:
Content-Security-Policy
base-uri'无'; default-src'self' https://s4.mylivechat.com ; child-src'un'; connect-src'self'; font-src'self' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com ;形式行动'自我'; frame-ancestors'none'; img-src'自我'数据:; media-src'self'; object-src'un';脚本-SRC '自' https://www.youtube.com https://maps.google.com https://www.google-analytics.com https://mylivechat.com https://s4.mylivechat.com https://maps.googleapis.com “不安全的内联” '不安全-EVAL'; style-src'self' https://fonts.googleapis.com https://s4.mylivechat.com https://maxcdn.bootstrapcdn.com “不安全的内联”
您添加到页面元数据的内容安全策略将被忽略,因为它存在于响应标头中。
您需要对响应标头中发送的CSP进行以下添加(以粗体显示)。
base-uri'无'; default-src'self' https://s4.mylivechat.com ; child-src'un'; connect-src'self'; font-src'self' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com ;形式行动'自我' 的 https://cipg.stanbicibtcbank.com/MerchantServices/MakePayment.aspx 强> ; frame-ancestors'none'; img-src'自我'数据: 的 https://s4.mylivechat.com 强> ; media-src'self'; object-src'un'; script-src'self' https://www.youtube.com https://maps.google.com https://www.google-analytics.com https://mylivechat.com https://s4.mylivechat.com https://maps.googleapis.com “不安全的内联” '不安全-EVAL'; style-src'self' https://fonts.googleapis.com https://s4.mylivechat.com https://maxcdn.bootstrapcdn.com “不安全直插”;
<meta http-equiv="Content-Security-Policy" content="form-action 'self'">