# Why is script-src: 'unsafe-inline' forbidden

**URL:** <https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291>\
**Category:** Development\
**Created:** [March 22, 2019, 5:30pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291 "2019-03-22T17:30:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluelemon](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/bluelemon/32/77685_2.png) [@bluelemon](https://discourse.mozilla.org/u/bluelemon)\
**Post date:** [March 22, 2019, 5:30pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291/1 "2019-03-22T17:30:55Z")

</div>

I’m displaying search engine results in the sidebar via an iframe and the results occasionally include inline script, so I added the above in the manifest.json file.

I’m now getting the following error message:

> Reading manifest: Error processing content\_security\_policy: SyntaxError: ‘script-src’ directive contains a forbidden ‘unsafe-inline’ keyword

Btw, I had also set the iframe’s sandbox attribute to ‘allow-scripts’.

Is there a way to fix this?

---

<div class="post-metadata">

**Author:** ![freaktechnik](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/freaktechnik/32/37766_2.png) [@freaktechnik](https://discourse.mozilla.org/u/freaktechnik)\
**Post date:** [March 22, 2019, 5:43pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291/2 "2019-03-22T17:43:05Z")

</div>

The way to fix this is not to have inline scripts. It sounds like these search engine results even have scripts that come from a remote location, which isn’t allowed either.

---

<div class="post-metadata">

**Author:** ![bluelemon](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/bluelemon/32/77685_2.png) [@bluelemon](https://discourse.mozilla.org/u/bluelemon)\
**Post date:** [March 22, 2019, 6:21pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291/3 "2019-03-22T18:21:52Z")

</div>

Sad thing is that functionality is lost, meaning that in certain cases images and video thumbnails don’t get displayed next to each result. Instead, you just get a white rectangle!

---

<div class="post-metadata">

**Author:** ![freaktechnik](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/freaktechnik/32/37766_2.png) [@freaktechnik](https://discourse.mozilla.org/u/freaktechnik)\
**Post date:** [March 22, 2019, 6:23pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291/4 "2019-03-22T18:23:40Z")

</div>

Why do those need to be loaded by inline scripts? That doesn’t sound like it should require inline JS.

---

<div class="post-metadata">

**Author:** ![bluelemon](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/bluelemon/32/77685_2.png) [@bluelemon](https://discourse.mozilla.org/u/bluelemon)\
**Post date:** [March 22, 2019, 6:34pm UTC](https://discourse.mozilla.org/t/why-is-script-src-unsafe-inline-forbidden/37291/5 "2019-03-22T18:34:14Z")

</div>

That’s a good question for those who design the search engines and how they present search results. All I can do is try to adapt so that users still get a good experience.

When removing ‘unsafe-inline’ from manifest.json using [ecosia.org](http://ecosia.org) in the sidebar:

 ![24](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/1/3/131f5634712cb3a79fd1b8b1a3c372dc1d6a33fb.jpeg)

When allowing ‘unsafe-inline’ in manifest.json, using [ecosia.org](http://ecosia.org) in the sidebar:

 ![01](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/f/7fff459f17f1780eb3be74b964c50ee74540e396.jpeg)

Yet, some scripts are still being blocked:

 ![40](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/4/6/46163fd0c80e52c0cabeebd8fc1d1829c699c917.jpeg)
