If you are the "Wikidata generic tree" tool developer, then you shouldn't load any third-party assets from third-party sites for privacy reasons.
The third-party assets should be loaded from either your own Toolforge application, or perhaps from a generic Wikimedia asset server (do we have that?).
In Scholia, we are loading D3 from https://scholia.toolforge.org/static/d3.v5.min.js (which may not be optimal).
/Finn
On 4/16/20 10:47 PM, Fabrizio Carrai wrote:
Today the "Wikidata generic tree" tool is not able to load the labels. My Chromium console reports:
/[Report Only] Refused to load the script 'https://d3js.org/d3.v3.min.js' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: filesystem: mediastream: wikibooks.org http://wikibooks.org *.wikibooks.org http://wikibooks.org wikidata.org http://wikidata.org *.wikidata.org http://wikidata.org wikimedia.org http://wikimedia.org *.wikimedia.org http://wikimedia.org wikinews.org http://wikinews.org *.wikinews.org http://wikinews.org wikipedia.org http://wikipedia.org *.wikipedia.org http://wikipedia.org wikiquote.org http://wikiquote.org *.wikiquote.org http://wikiquote.org wikisource.org http://wikisource.org *.wikisource.org http://wikisource.org wikiversity.org http://wikiversity.org *.wikiversity.org http://wikiversity.org wikivoyage.org http://wikivoyage.org *.wikivoyage.org http://wikivoyage.org wiktionary.org http://wiktionary.org *.wiktionary.org http://wiktionary.org *.wmflabs.org http://wmflabs.org wikimediafoundation.org http://wikimediafoundation.org mediawiki.org http://mediawiki.org *.mediawiki.org http://mediawiki.org wss://tools.wmflabs.org http://tools.wmflabs.org". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback./ / / Same result with FireFox.
Thanks for any support that anybody can provide
Ciao /-- / /Fabrizio/
Wikidata mailing list Wikidata@lists.wikimedia.org https://lists.wikimedia.org/mailman/listinfo/wikidata