Squareup.com issue - Content Security Policy

This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.
6 years ago
I am on version 4.  Trying to use SquareUp and getting this error on the checkout page (when looking at the console):
Content Security Policy: The page’s settings blocked the loading of a resource at blob:https://connect.squareup.com/<removed a code> (“script-src 'unsafe-inline' https://js.squareup.com”).

This is causing the page to give the following error when I try to checkout:
Failed to get the card nonce

Thoughts?
6 years ago
*bump*, still looking but not understanding how this is supposed to work in this setup.
6 years ago
1. What is your site URL?
2. Do you have "Content-Security-Policy" meta tag on your page? If yes, please see https://stackoverflow.com/questions/37298608/content-security-policy-the-pages-settings-blocked-the-loading-of-a-resource
6 years ago
www.bcrl.org

I have removed the SquareUp option, I can reproduce it locally as well.  No meta tag on the site and I don't see it being setup in code either.

I think it has to do with an iFrame inserted by the plugin.

With that being said, I am moving to BrainTree right now. Verified it works in dev, just waiting for a merchant account to be created. I'd rather use SquareUp, but I need something that works.

I'd like to know if anybody has SquareUp working on 4.0.
6 years ago
Hi,

I have SqureUp working fine on 1 website, but now I am facing an issue with a different site - the error message says 'Failed to get the card nonce'.

Any idea what this means?
6 years ago
[email protected] wrote:
Hi,

I have SqureUp working fine on 1 website, but now I am facing an issue with a different site - the error message says 'Failed to get the card nonce'.

Any idea what this means?


I just disabled the 'One-page checkout' plugin from Nop-Templates and it cleared the error.
6 years ago
On version 4, you have it working?
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.