<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers in APIs &amp; Integrations</title>
    <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/410988#M40705</link>
    <description>&lt;P&gt;Same issue is causing your scripts such as forms.hubspot.com from loading in Firefox, Chrome and Safari (browsers detecting it as an invalid CORS request and blocking it), because of this our lead captures from forms aren't working.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 17:16:12 GMT</pubDate>
    <dc:creator>04705</dc:creator>
    <dc:date>2021-02-19T17:16:12Z</dc:date>
    <item>
      <title>Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/400627#M39633</link>
      <description>&lt;P&gt;When embedding a Hubspot form in a website, Chrome is showing the following issues in Devtools:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refused to frame app.hubspot.com because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self'".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried several changes to my own site's Content Security Policy however I am sure this is because the Content-Security-Policy-Report-Only is incorrectly configures on the domain app.hubspot.com where this is the directive:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;frame-ancestors 'self'; report-uri ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I understand how frame-ancestors works, this directive is basically saying that only app.hubspot.com can use the reporting API? However the idea of the Reporting API is that clients send their issues to it when an error or issues occrurs in their browser. Hence I believe the correct change to remove these errors in clients browsers would be to remove the frame-ancestorsdirective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More information is available here:&amp;nbsp;&lt;A href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy-Report-Only" target="_blank" rel="noopener"&gt;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy-Report-Only&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 11:56:07 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/400627#M39633</guid>
      <dc:creator>AndrewHo</dc:creator>
      <dc:date>2021-01-18T11:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/401114#M39670</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/159430"&gt;@AndrewHo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Welcome to the Community!&lt;/P&gt;
&lt;P&gt;Could you send a link to where the form is embedded so we can take a look?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:25:19 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/401114#M39670</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-01-19T18:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/404687#M40065</link>
      <description>&lt;P&gt;I also have the same error, plus I cannot see the form properly in mobile... if someone can help, it would be very appreciated. The link is&amp;nbsp;&lt;A href="https://toscanabike.it/escursioni_mtb/da-lucca-a-viareggio-in-mountain-bike-nuova-variante/" target="_blank"&gt;https://toscanabike.it/escursioni_mtb/da-lucca-a-viareggio-in-mountain-bike-nuova-variante/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanx&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 18:50:12 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/404687#M40065</guid>
      <dc:creator>toscanabike</dc:creator>
      <dc:date>2021-01-29T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/405084#M40091</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/162944"&gt;@toscanabike&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I am seeing an error on your site, but it is not the same.&lt;/P&gt;
&lt;P&gt;It is &lt;STRONG&gt;&lt;EM&gt;Uncaught TypeError: hbspt.forms.create is not a function&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/112545"&gt;@LisbethN&lt;/a&gt; asked the same question &lt;A href="https://community.hubspot.com/t5/APIs-Integrations/Error-quot-ReferenceError-hbspt-is-not-defined-quot-with-embed/td-p/305533" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;I would look at the steps in that post to see if that helps out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 18:07:34 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/405084#M40091</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-02-01T18:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408458#M40441</link>
      <description>&lt;P&gt;Hi, I'm having the same issue. Page:&amp;nbsp;&lt;A href="https://www.kaimaging.com/medical-solutions/reveal-35c-medical/" target="_blank"&gt;https://www.kaimaging.com/medical-solutions/reveal-35c-medical/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Content Security Policy of your site blocks some resources because their origin is not included in the content security policy header&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How's the best way to solve this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:04:23 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408458#M40441</guid>
      <dc:creator>FFraga</dc:creator>
      <dc:date>2021-02-11T15:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408475#M40442</link>
      <description>&lt;P&gt;I am having this same issue! Has anyone managed to resolve it?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:30:45 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408475#M40442</guid>
      <dc:creator>GCiampa</dc:creator>
      <dc:date>2021-02-11T15:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408872#M40490</link>
      <description>&lt;P&gt;The best bet would be work with your site admin to update the content security policy&lt;/P&gt;
&lt;P&gt;Here is some &lt;A href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; on it.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 15:45:54 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/408872#M40490</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-02-12T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/410584#M40678</link>
      <description>&lt;P&gt;The original poster is correct, this needs to be handled by Hubspot. The frame-ancestors content security policy setting is on Hubspot's side to change. In Hubspot's CSP for `&lt;A href="https://app.hubspot.com/" target="_blank" rel="noopener"&gt;https://app.hubspot.com/&lt;/A&gt;` frame-ancestors is set to 'self'. This means that `&lt;A href="https://app.hubspot.com`" target="_blank" rel="noopener"&gt;https://app.hubspot.com`&lt;/A&gt;&amp;nbsp;is only allowed to be loaded on app.hubspot.com itself and not in an iframe on any other domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when you use the form embed code it tries to load `&lt;A href="https://app.hubspot.com/forms-next-v2-captcha`" target="_blank" rel="noopener"&gt;https://app.hubspot.com/forms-next-v2-captcha`&lt;/A&gt;&amp;nbsp;as part of the payload. So this either needs to be moved to another domain that is allowed to be embedded in iframes or remove the frame-ancestors directive from the app.hubspot.com CSP.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 17:50:07 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/410584#M40678</guid>
      <dc:creator>tinyfly</dc:creator>
      <dc:date>2021-02-18T17:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/410988#M40705</link>
      <description>&lt;P&gt;Same issue is causing your scripts such as forms.hubspot.com from loading in Firefox, Chrome and Safari (browsers detecting it as an invalid CORS request and blocking it), because of this our lead captures from forms aren't working.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 17:16:12 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/410988#M40705</guid>
      <dc:creator>04705</dc:creator>
      <dc:date>2021-02-19T17:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/411519#M40764</link>
      <description>&lt;P&gt;Hello, we're having the exact same issue with the Content Security policy. Has anyone resolved this yet?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 22:12:17 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/411519#M40764</guid>
      <dc:creator>Dpontarelli</dc:creator>
      <dc:date>2021-02-22T22:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/411999#M40832</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;This seems like it can only be fixed on HubSpot's side.&amp;nbsp;&lt;BR /&gt;Could you confirm if HubSpot acknowledges that's the case and if they plan to work on a fix?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 21:11:19 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/411999#M40832</guid>
      <dc:creator>CAndres</dc:creator>
      <dc:date>2021-02-23T21:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412126#M40836</link>
      <description>&lt;P&gt;Hi all, we managed to resolve this issue. In our case, it was because our site did not support iframes. Every Hubspot code is essentially, in an iframe. It took some work form our developer but it was a pretty quick fix.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 06:44:29 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412126#M40836</guid>
      <dc:creator>GCiampa</dc:creator>
      <dc:date>2021-02-24T06:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412165#M40840</link>
      <description>&lt;P&gt;That's great news, GCiampa. Could your developer provide any guidance as to what the fix was? We are really struggling here with this same issue and would love to see if we could replicate your approach.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 09:14:14 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412165#M40840</guid>
      <dc:creator>IWatt</dc:creator>
      <dc:date>2021-02-24T09:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412392#M40855</link>
      <description>&lt;P&gt;Hey all, The team is looking into this.&amp;nbsp; I will report back when I have an update.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 16:18:37 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/412392#M40855</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-02-24T16:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414124#M41015</link>
      <description>&lt;P&gt;Hi Dennis, did you solve this issue? now even the messages are not delivered via HubSpot forms&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 13:22:53 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414124#M41015</guid>
      <dc:creator>Jeff_videommerc</dc:creator>
      <dc:date>2021-03-02T13:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414171#M41028</link>
      <description>&lt;P&gt;The team is looking into it.&amp;nbsp; Will report back when I have confirmed the resolution&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:23:17 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414171#M41028</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-03-02T15:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414332#M41048</link>
      <description>&lt;P&gt;Same situation here. I tried to update things on my end but it did not fix the issue. Hoping for a fix on HubSpot's side.&lt;/P&gt;&lt;P&gt;&lt;A href="https://kpstaffing.com/" target="_blank" rel="noopener"&gt;https://kpstaffing.com/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 22:11:24 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/414332#M41048</guid>
      <dc:creator>philipcron</dc:creator>
      <dc:date>2021-03-02T22:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/417523#M41424</link>
      <description>&lt;P&gt;I have the same issue. Any news?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 14:54:39 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/417523#M41424</guid>
      <dc:creator>AlbertoSM</dc:creator>
      <dc:date>2021-03-12T14:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/417578#M41427</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/84505"&gt;@AlbertoSM&lt;/a&gt; , not yet, but I do know that it is being worked on.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 17:16:19 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/417578#M41427</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-03-12T17:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content-Security-Policy-Report-Only from app.hubspot.com is reporting errors to browsers</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/418836#M41502</link>
      <description>&lt;P&gt;OK everyone, I have been told that a fix has been deployed.&amp;nbsp; Let me know what you all are seeing out there now &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 20:11:59 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Content-Security-Policy-Report-Only-from-app-hubspot-com-is/m-p/418836#M41502</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-03-15T20:11:59Z</dc:date>
    </item>
  </channel>
</rss>

