Hi,
I cannot get a new Matomo instance to work on a server that has no unsafe-eval rule in the CSP. The UI renders incompletely (no data), and the browser console shows “uncaught EvalError” messages.
The only similar issue I found here is https://forum.matomo.org/t/problems-with-tight-csp-policies/28405; however, this thread died with no solution.
I would be grateful for any hint that helps me fixing this. Thanks.
Uncaught EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' ... (couple of (sub)domains following here)".
The failing script is index.php, module Proxy, action getCoreJs:
https://…/index.php?module=Proxy&action=getCoreJs&cb=b479f5931ab033dbda9d313c2ec3b650