Content Security Policy... [Report Only] Refused to load the font

Highlighted
Shopify Partner
36 0 3

Hey All,

I am getting ​20 or so Javascript console errors that display the below, I was wondering if anyone had encountered this before? 

"[Report Only] Refused to load the font... because it violates the following Content Security Policy directive: "font-src 'self' *".

It's coming up in relation to both modernizr and the index. 

I am currently using web fonts from "Cloud Typography", the errors seem to be relatively new and were not present when I first applied the service to the Shopify website.

Thanks,

Sam

2 Likes
Highlighted
New Member
1 0 0

Having same issue, but I am using Adobe's Typekit. 

0 Likes
Highlighted
New Member
4 0 0

Same here Emmy. I hope we can get this taken care of ASAP.

0 Likes
Highlighted
Shopify Expert
9872 100 1710

The bigger questions should be:

  • is the font loading?
  • are the errors shown causing something else on the site to not work?

 

★ Winning Partner of the Build a Business competition. ★ http://freakdesign.com.au
0 Likes
Highlighted
Shopify Partner
36 0 3

Yes the font is loading and no it does not seem to be effecting anything. Do you think it's okay to ignore then?

Thanks :)

Sam

0 Likes
Highlighted
New Member
4 0 0

Mine is not being loaded. I've tried Typekit, EdgeFonts as well. Same issue. Shopify issue?

0 Likes
Highlighted
Shopify Partner
18 0 2

Same here. My fonts from typekit on www.madeofsundays.com load just fine, but the errors are there. I assume it has something to do with the security policy of the general setup? 

0 Likes
Highlighted
Shopify Partner
2 0 0

Also having the same issue - but my fonts do appear to be loading. Mostly just annoying to develop new features when I have to sift through the noise in the developer tools window. Seems shopify-wide to me.

0 Likes
Highlighted
Shopify Expert
9872 100 1710

The error is set to report only so it won't impact other scripts on the site. This is not something you'll be able to change / adjust yourself, but there is some info on the Adobe Typekit help pages should you be curious.

All the sites I've seen so far with typekit in place load the font correctly across browsers and platforms. It would bother me seeing the report in the console too, so I feel the inner developer annoyance on that one ;)

@Andrew: Yes, it should be across the platform since everyone will share the same CSP policy. 

@Matthew: Now if it's failing completely I would think you've got issues with the implemetation and not what others are seeing here. I checked your site and don't see typekit being used at all. Perhaps you've removed it since your post.

★ Winning Partner of the Build a Business competition. ★ http://freakdesign.com.au
1 Like
Highlighted
Shopify Partner
3 0 1

I have the same issue. When you load page using https, error disappears

1 Like