Skip to content

Commit f871c16

Browse files
authored
Document that Cloudflare Rocket Loader must be disabled (#8026)
1 parent fa7caee commit f871c16

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

‎docs/guide.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
- [Using Let's Encrypt with NGINX](#using-lets-encrypt-with-nginx)
1010
- [Using a self-signed certificate](#using-a-self-signed-certificate)
1111
- [TLS 1.3 and Safari](#tls-13-and-safari)
12+
- [Cloudflare Rocket Loader](#cloudflare-rocket-loader)
1213
- [External authentication](#external-authentication)
1314
- [HTTPS and self-signed certificates](#https-and-self-signed-certificates)
1415
- [Accessing web services](#accessing-web-services)
@@ -269,6 +270,26 @@ than TLS 1.3 you will need to add support for TLS 1.2 since Safari does not
269270
support TLS 1.3 for web sockets at the time of writing. If this is the case you
270271
should see OSSStatus: 9836 in the browser console.
271272

273+
### Cloudflare Rocket Loader
274+
275+
If you serve code-server through Cloudflare, disable Rocket Loader for that
276+
hostname. Rocket Loader rewrites inline `<script>` tags at the edge and
277+
re-injects them from its own loader, and the re-injected scripts do not carry
278+
the nonce in code-server's Content Security Policy, so the browser blocks them.
279+
The result is a blank page: every request returns HTTP 200 and the server logs
280+
look healthy, and the only console output is `Cannot determine URI for module
281+
id!`.
282+
283+
Scope it with a Configuration Rule rather than turning it off zone-wide:
284+
285+
```
286+
Expression: (http.host eq "code.example.com")
287+
Setting: Rocket Loader -> Off
288+
```
289+
290+
Adding `'unsafe-inline'` to the policy does not help, because CSP ignores it
291+
whenever a nonce or hash is present.
292+
272293
## External authentication
273294

274295
If you want to use external authentication mechanism (e.g., Sign in with

0 commit comments

Comments
 (0)