Skip to content

CSP violation on every page in Firefox: prefetch of CustomPickerElement chunk blocked by default-src 'none' #2558

Description

@alex-di-96

Version: Bookmarks 17.0.0, Nextcloud 35.0.1, Firefox

What happens

On every Nextcloud page (the references entry is loaded globally for the smart picker) Firefox logs:

Content-Security-Policy: The page's settings blocked the loading of a resource (default-src) at
…/apps/bookmarks/js/bookmarks-src_components_CustomPickerElement_vue.js because it violates the following directive: "default-src 'none'"

Why

bookmarks-references.js contains webpack's prefetch runtime (__webpack_require__.F.j → <link rel="prefetch" as="script">)
for the CustomPickerElement chunk, i.e. the dynamic import uses webpackPrefetch: true.
Firefox checks rel=prefetch against default-src (there is no prefetch-src anymore), and Nextcloud's CSP sets
default-src 'none', so the prefetch is always blocked. The chunk is still loaded on demand, so the prefetch
never helps and only produces noise.

Suggested fix

Drop webpackPrefetch: true (magic comment) from the CustomPickerElement dynamic import in the references entry.
We verified locally that disabling the prefetch runtime removes the error and the picker still works.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions