Skip to content
All documentation pages

Reference

Content Security Policy

If your site sends a Content-Security-Policy header, allow the CDN the tracker loads from and the collector it sends to.

The two sources

Add these sources to your existing directives rather than replacing them:

Content-Security-Policy
script-src 'self' https://cdn-stg.webmetric.io;
connect-src 'self' https://in-stg.webmetric.io;
What each source is for
DirectiveSourceWhy
script-srchttps://cdn-stg.webmetric.iob.js, and r.js and s.js when replay or page captures run. All three load from the same place.
connect-srchttps://in-stg.webmetric.ioEvents, the project’s settings, replay chunks and page captures.

As a meta tag

If you cannot set headers, the same policy works as a meta tag in the <head>, placed before the script tag:

Meta tagHTML
<meta http-equiv="Content-Security-Policy"
  content="script-src 'self' https://cdn-stg.webmetric.io; connect-src 'self' https://in-stg.webmetric.io">

Inline code

The script tag itself needs no inline script. If you add the early-call stub from the SDK reference inline, allow it with a nonce or a hash, or serve it as a file from your own origin.

Subresource Integrity

https://cdn-stg.webmetric.io/v1/b.js always serves the latest release, so an integrity hash on it would stop it loading as soon as the file changes. To pin a release, load b.js from that release’s own folder and add the integrity value listed in its release notes, with crossorigin="anonymous". A pinned file never updates, so upgrading becomes your job.