# React frontend: Setting content-security-policy in the index.html doesn't seem to do anything?

**URL:** <https://forum.dfinity.org/t/react-frontend-setting-content-security-policy-in-the-index-html-doesnt-seem-to-do-anything/19257>\
**Category:** Getting Started\
**Tags:** Frontend\
**Created:** [April 3, 2023, 3:39pm UTC](https://forum.dfinity.org/t/react-frontend-setting-content-security-policy-in-the-index-html-doesnt-seem-to-do-anything/19257 "2023-04-03T15:39:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![karim](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/karim/32/4680_2.png) [@karim](https://forum.dfinity.org/u/karim)\
**Post date:** [April 3, 2023, 3:39pm UTC](https://forum.dfinity.org/t/react-frontend-setting-content-security-policy-in-the-index-html-doesnt-seem-to-do-anything/19257/1 "2023-04-03T15:39:31Z")

</div>

I have been using React as a frontend on the IC for quite some time and usually load images as Nat8 and then turn them into a data URL (blob). This used to work. I now noticed with a new project that the content security policy doesn’t allow image sources as blob and so I tried to set it in the index.html but the changes don’t have any effect. I also get this warning “out of the box” with any new React installation:

```auto
Refused to load the script 'https://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/js/select2.min.js' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

```

Afaik this tag in the index.html should sort this out, but it doesn’t:

```auto
<meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-eval' cdn.jsdelivr.net">

```

It seems that the security policy is being set somewhere else. Does anybody know how I can adjust it?

---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [April 3, 2023, 5:06pm UTC](https://forum.dfinity.org/t/react-frontend-setting-content-security-policy-in-the-index-html-doesnt-seem-to-do-anything/19257/2 "2023-04-03T17:06:42Z")

</div>

It’s a side effect of breaking changes of dfx v0.13.1. Now when you create a new project it gets created with a restrictive CSP. You can disable it, I understand did not try my self, in `.ic-assets.json`. Not sure if you have to clean and redeploy afterwards, checkout the release notes.

> [@Dfx 0.13.1 is promoted with breaking changes](https://forum.dfinity.org/t/dfx-0-13-1-is-promoted-with-breaking-changes/18743/3):
>
> Yes, you can overwrite any of these. In the first place, you’ll only see these values in .ic-assets.json in new projects, meaning you ran dfx new with dfx 0.13.1. In the second, you are free to edit the values or overwrite the header values for specific files or directories.

---

<div class="post-metadata">

**Author:** ![karim](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/karim/32/4680_2.png) [@karim](https://forum.dfinity.org/u/karim)\
**Post date:** [April 3, 2023, 5:45pm UTC](https://forum.dfinity.org/t/react-frontend-setting-content-security-policy-in-the-index-html-doesnt-seem-to-do-anything/19257/3 "2023-04-03T17:45:37Z")

</div>

Thanks a lot! Followed these instructions and got it to work: [headers not updated · Issue #3053 · dfinity/sdk · GitHub](https://github.com/dfinity/sdk/issues/3053)
