结账页控制台出现Refused to load script,支付组件空白。不能用全局unsafe-inline或关闭CSP解决,应精确授权资源来源。
排查路径
- 从浏览器控制台记录被阻止的script、frame、connect或img来源,区分支付生产域与测试域。
- 在支付模块csp_whitelist.xml为对应policy添加精确host;内联脚本优先改为外部文件或使用Magento nonce/hash机制。
落地修复
- 支付iframe、API和风控像素可能属于不同policy,逐项添加且只允许HTTPS官方域名。
- 部署后清config/FPC并检查响应Content-Security-Policy,确认没有重复代理Header覆盖Magento配置。
rg -n 'csp_whitelist|content-security-policy' app/code app/designcurl -sSI https://shop.example/checkout/ | grep -i content-security-policybin/magento cache:clean config full_page
完成标准
支付组件完整加载并可下单,控制台无相关CSP错误,未授权测试域和任意内联脚本仍被阻止。

