fix: allow Google Fonts in CSP #20
Reference in New Issue
Block a user
Delete Branch "fix/csp-google-fonts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The
style-srcandfont-srcCSP directives were set toselfonly, which blockedfonts.googleapis.com(stylesheet) andfonts.gstatic.com(font files) from loading in production.This caused the site to render with fallback system fonts — Space Grotesk, Inter, and Fira Code were all silently blocked.
Fix: add
https://fonts.googleapis.comtostyle-srcandhttps://fonts.gstatic.comtofont-src.