alexcambose / x-frame-options

x-frame-options bypass

Home Page:https://medium.com/@alexcambose/bypassing-x-frame-options-4934dd852618

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Sites will not load properly. Many Errors.

JASFramework opened this issue · comments

The project works initially but overall fails. It does not load fonts, CSS, and JS. Below are the errors I got from testing one site.

Please fix!

Thanks,

JAS

Refused to load the stylesheet '<URL>' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' <URL>". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/css/site.light.min.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/css/lobby.light.min.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/piece-css/cburnett.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/css/site.light.min.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/css/lobby.light.min.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the stylesheet 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/piece-css/cburnett.css' because it violates the following Content Security Policy directive: "style-src 'self' 'unsafe-inline' https://lichess1.org". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback.

localhost/:1 Refused to load the font 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/font/lichess.woff2' because it violates the following Content Security Policy directive: "default-src 'self' https://lichess1.org". Note that 'font-src' was not explicitly set, so 'default-src' is used as a fallback.

localhost/:1 Refused to load the font 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/font/lichess.chess.woff2' because it violates the following Content Security Policy directive: "default-src 'self' https://lichess1.org". Note that 'font-src' was not explicitly set, so 'default-src' is used as a fallback.

localhost/:1 Refused to load the script 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/compiled/lichess.min.js' because it violates the following Content Security Policy directive: "script-src 'nonce-UXzA4tay8Sk8VgDorZCKymGw' 'self' https://lichess1.org". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

localhost/:1 Refused to load the script 'http://localhost/?url=https://lichess1.org/assets/_jq4ChM/compiled/lobby.min.js' because it violates the following Content Security Policy directive: "script-src 'nonce-UXzA4tay8Sk8VgDorZCKymGw' 'self' https://lichess1.org". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

localhost/:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
localhost/:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
localhost/:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
1:3 Refused to load the script 'https://ssl.google-analytics.com/ga.js' because it violates the following Content Security Policy directive: "script-src 'nonce-UXzA4tay8Sk8VgDorZCKymGw' 'self' https://lichess1.org". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

(anonymous) @ 1:3
1:3 Refused to load the script 'http://www.pagespeed-mod.com/v1/taas?id=cs&ak=55c85bbdd6e4d21e7278fbbbb89a9502&si=fb4741a02e044f61940836e20590e7f6&tag=1005&rand=75159da722950d6d1bed603b1040529e&ord=1372444829828016.8' because it violates the following Content Security Policy directive: "script-src 'nonce-UXzA4tay8Sk8VgDorZCKymGw' 'self' https://lichess1.org". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

(anonymous) @ 1:3
?url=http://lichess.org/:6 Uncaught (in promise) ReferenceError: LichessLobby is not defined
    at ?url=http://lichess.org/:6
localhost/:1 Refused to load manifest from 'http://localhost/?url=http://lichess.org/manifest.json' because it violates the following Content Security Policy directive: "default-src 'self' https://lichess1.org". Note that 'manifest-src' was not explicitly set, so 'default-src' is used as a fallback.

/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-32.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-64.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-128.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-192.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-256.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
/?url=https://lichess1.org/assets/_jq4ChM/logo/lichess-favicon-512.png:1 Failed to load resource: net::ERR_CONNECTION_REFUSED
localhost/:1 Refused to load manifest from 'http://localhost/?url=http://lichess.org/manifest.json' because it violates the following Content Security Policy directive: "default-src 'self' https://lichess1.org". Note that 'manifest-src' was not explicitly set, so 'default-src' is used as a fallback.