|
9 | 9 | - [Using Let's Encrypt with NGINX](#using-lets-encrypt-with-nginx) |
10 | 10 | - [Using a self-signed certificate](#using-a-self-signed-certificate) |
11 | 11 | - [TLS 1.3 and Safari](#tls-13-and-safari) |
| 12 | + - [Cloudflare Rocket Loader](#cloudflare-rocket-loader) |
12 | 13 | - [External authentication](#external-authentication) |
13 | 14 | - [HTTPS and self-signed certificates](#https-and-self-signed-certificates) |
14 | 15 | - [Accessing web services](#accessing-web-services) |
@@ -269,6 +270,26 @@ than TLS 1.3 you will need to add support for TLS 1.2 since Safari does not |
269 | 270 | support TLS 1.3 for web sockets at the time of writing. If this is the case you |
270 | 271 | should see OSSStatus: 9836 in the browser console. |
271 | 272 |
|
| 273 | +### Cloudflare Rocket Loader |
| 274 | + |
| 275 | +If you serve code-server through Cloudflare, disable Rocket Loader for that |
| 276 | +hostname. Rocket Loader rewrites inline `<script>` tags at the edge and |
| 277 | +re-injects them from its own loader, and the re-injected scripts do not carry |
| 278 | +the nonce in code-server's Content Security Policy, so the browser blocks them. |
| 279 | +The result is a blank page: every request returns HTTP 200 and the server logs |
| 280 | +look healthy, and the only console output is `Cannot determine URI for module |
| 281 | +id!`. |
| 282 | + |
| 283 | +Scope it with a Configuration Rule rather than turning it off zone-wide: |
| 284 | + |
| 285 | +``` |
| 286 | +Expression: (http.host eq "code.example.com") |
| 287 | +Setting: Rocket Loader -> Off |
| 288 | +``` |
| 289 | + |
| 290 | +Adding `'unsafe-inline'` to the policy does not help, because CSP ignores it |
| 291 | +whenever a nonce or hash is present. |
| 292 | + |
272 | 293 | ## External authentication |
273 | 294 |
|
274 | 295 | If you want to use external authentication mechanism (e.g., Sign in with |
|
0 commit comments