Skip to content

Commit dead830

Browse files
committed
fix(deploy): allow WebContainer CDN import and enable cross-origin isolation
The Cloudflare Pages CSP blocked the dynamic import of @webcontainer/api from cdn.jsdelivr.net in wc-bridge.js, silently breaking terminal creation in the deployed web build. Whitelist the CDN in script-src and add COEP so WebContainer boots with full require-corp isolation instead of falling back to degraded mode.
1 parent 4a4dcb2 commit dead830

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎scripts/deploy-cloudflare.sh‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,6 +234,7 @@ cat > "${STAGE}/_headers" <<'EOF'
234234
X-Content-Type-Options: nosniff
235235
Referrer-Policy: no-referrer
236236
Cross-Origin-Opener-Policy: same-origin-allow-popups
237+
Cross-Origin-Embedder-Policy: credentialless
237238
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self' https: wss: blob:; worker-src 'self' blob:; frame-src 'self' https:; object-src 'none'; base-uri 'self'
238239
239240
/vscode/*

0 commit comments

Comments
 (0)