Version: Bookmarks 17.0.0, Nextcloud 35.0.1, Firefox
What happens
On every Nextcloud page (the references entry is loaded globally for the smart picker) Firefox logs:
Content-Security-Policy: The page's settings blocked the loading of a resource (default-src) at
…/apps/bookmarks/js/bookmarks-src_components_CustomPickerElement_vue.js because it violates the following directive: "default-src 'none'"
Why
bookmarks-references.js contains webpack's prefetch runtime (__webpack_require__.F.j → <link rel="prefetch" as="script">)
for the CustomPickerElement chunk, i.e. the dynamic import uses webpackPrefetch: true.
Firefox checks rel=prefetch against default-src (there is no prefetch-src anymore), and Nextcloud's CSP sets
default-src 'none', so the prefetch is always blocked. The chunk is still loaded on demand, so the prefetch
never helps and only produces noise.
Suggested fix
Drop webpackPrefetch: true (magic comment) from the CustomPickerElement dynamic import in the references entry.
We verified locally that disabling the prefetch runtime removes the error and the picker still works.
Version: Bookmarks 17.0.0, Nextcloud 35.0.1, Firefox
What happens
On every Nextcloud page (the
referencesentry is loaded globally for the smart picker) Firefox logs:Why
bookmarks-references.jscontains webpack's prefetch runtime (__webpack_require__.F.j→<link rel="prefetch" as="script">)for the
CustomPickerElementchunk, i.e. the dynamic import useswebpackPrefetch: true.Firefox checks
rel=prefetchagainstdefault-src(there is noprefetch-srcanymore), and Nextcloud's CSP setsdefault-src 'none', so the prefetch is always blocked. The chunk is still loaded on demand, so the prefetchnever helps and only produces noise.
Suggested fix
Drop
webpackPrefetch: true(magic comment) from theCustomPickerElementdynamic import in the references entry.We verified locally that disabling the prefetch runtime removes the error and the picker still works.