Reference
Content Security Policy
If your site sends a Content-Security-Policy header, allow the CDN the tracker loads from and the collector it sends to.
The two sources
Add these sources to your existing directives rather than replacing them:
script-src 'self' https://cdn-stg.webmetric.io;
connect-src 'self' https://in-stg.webmetric.io;| Directive | Source | Why |
|---|---|---|
script-src | https://cdn-stg.webmetric.io | b.js, and r.js and s.js when replay or page captures run. All three load from the same place. |
connect-src | https://in-stg.webmetric.io | Events, the project’s settings, replay chunks and page captures. |
As a meta tag
If you cannot set headers, the same policy works as a meta tag in the <head>, placed before the script tag:
<meta http-equiv="Content-Security-Policy"
content="script-src 'self' https://cdn-stg.webmetric.io; connect-src 'self' https://in-stg.webmetric.io">Inline code
The script tag itself needs no inline script. If you add the early-call stub from the SDK reference inline, allow it with a nonce or a hash, or serve it as a file from your own origin.
Subresource Integrity
https://cdn-stg.webmetric.io/v1/b.js always serves the latest release, so an integrity hash on it would stop it loading as soon as the file changes. To pin a release, load b.js from that release’s own folder and add the integrity value listed in its release notes, with crossorigin="anonymous". A pinned file never updates, so upgrading becomes your job.