Skip to content

Decentraleyes breaks PaymentEvolution

See this error in the console:

Refused to load the script 'chrome-extension://ldpochfccmkkmhdbclfhpagapcfdljkj/resources/jquery/1.9.1/jquery.min.jsm?_=42d2efbb24d8aa28ce2e64db' because it violates the following Content Security Policy directive: "default-src 'self' data: https://snap.licdn.com https://*.clarity.ms https://*.svc.dynamics.com https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube.com https://ajax.aspnetcdn.com https://player.vimeo.com https://*.paymentevolution.com https://paymentevolution.com https://*.fontawesome.com https://ssl.google-analytics.com https://*.googleapis.com https://maxcdn.bootstrapcdn.com https://js.stripe.com 'unsafe-inline' 'unsafe-eval' https://*.pingdom.net https://*.zendesk.com https://*.zdassets.com". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback.

The site loads the resources from URL https://secure.paymentevolution.com/client-scripts/.

Excluding domain secure.paymentevolution.com works.

Edited by Raman Gupta