frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Claude web blocked its assets visit via csp?

5•xgstation•5h ago
returned CSP header as following while all assets access to `https://assets-proxy.anthropic.com` is blocked

    script-src 'strict-dynamic' https: 'nonce-0f2f/yV7CL8nKlXr/lFMPA==' https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com https://maps.googleapis.com https://maps.gstatic.com 'wasm-unsafe-eval'; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; block-all-mixed-content; img-src 'self' data: blob: *.anthropic.com *.claude.ai *.claude.com *.ant.dev *.gstatic.com * https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://video-messages.intercomcdn.com https://messenger-apps.intercom.io https://messenger-apps.eu.intercom.io https://messenger-apps.au.intercom.io https://*.intercom-attachments-1.com https://*.intercom-attachments.eu https://*.au.intercom-attachments.com https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://static.intercomassets.eu https://static.au.intercomassets.com; frame-src a-cdn.claude.ai a.claude.ai a.claude-ai.staging.ant.dev b.stripecdn.com embedded-dashboards.metronome.com forms.hsforms.com googletagmanager.com js.stripe.com m.stripe.network newassets.hcaptcha.com pay.google.com r.stripe.com www.google.com accounts.google.com www.youtube-nocookie.com https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://www.claudeusercontent.com https://www.claudemcpclient.com *.claudemcpcontent.com https://claude.ai; font-src 'self' assets.claude.ai https://js.intercomcdn.com https://fonts.intercomcdn.com; form-action 'self' https://forms.hsforms.com https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io; media-src 'self' cdn.sanity.io https://assets.claude.ai https://js.intercomcdn.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com; upgrade-insecure-requests

Comments

qrian•5h ago
yeah same here
yogipatel•5h ago
DNS for that host is borked. Obligatory "it's always DNS"

Thank HN: You helped save 33k lives

587•chaseadam17•11h ago•71 comments

Tell HN: Attackers using Google parental controls to prevent account recovery

8•TazeTSchnitzel•2h ago•0 comments

Ask HN: How do you motivate your humans to stop AI-washing their emails?

23•causal•11h ago•30 comments

Ask HN: How do you overcome imposter syndrome?

5•fdneng•4h ago•4 comments

Ask HN: Claude web blocked its assets visit via csp?

5•xgstation•5h ago•2 comments

Picknar – Lightweight YouTube Thumbnail Extractor (No Login, No API Key)

2•Picknar•11h ago•0 comments

Grand Time: Time-Based Models in Decentralized Trust

2•AGsist•11h ago•0 comments

Watching an elderly relative trying to use the modern web

43•ColinWright•1d ago•18 comments

Ask HN: Why is my Claude experience so bad? What am I doing wrong?

77•moomoo11•4d ago•115 comments

Ask HN: Companies that advertise being a "best place to work", is it a red flag?

12•jrs235•1d ago•13 comments

Ask HN: How do companies that use Cursor handle compliance?

7•Poomba•1d ago•3 comments

Top non-ad google result for "polymarket" in Australia is a crypto scam

16•rtrgrd•2d ago•2 comments

Ask HN: Are there examples of 3D printing data onto physical surfaces?

17•catapart•4d ago•33 comments

Ask HN: Why is YouTube's recommendation system so bad?

14•mr-pink•1d ago•13 comments

Ask HN: Do global AGENTS.md with coding principles make sense?

4•endorphine•1d ago•3 comments

Ask HN: Ranking sliders on a personal blog?

12•incognito124•2d ago•1 comments

What web businesses will continue to make money post AI?

15•surume•2d ago•30 comments

Ask HN: Info on the 1982 Apple 2 text game Abuse?

6•jmount•3d ago•2 comments

Tell HN: Microsoft Edge self-destroys updating it in Debian based distros

7•usr1106•1d ago•1 comments

Ask HN: Share your vibe coded project

5•firefoxd•2d ago•9 comments

Ask HN: What happens after the AI bubble bursts?

38•101008•1d ago•41 comments

Ask HN: Stripe is asking for bank statements to check financial health

10•kinj28•3d ago•9 comments

Ask HN: How's Business These Days for Fiverr Freelancers?

13•burnerToBetOut•1d ago•5 comments

Ask HN: LLMs helping you read papers and books

8•amelius•2d ago•4 comments

Ask HN: Want to move to use a "dumb" phone. How to make the switch?

12•absoluteunit1•3d ago•13 comments

Ask HN: What explains the recent surge in LLM coding capabilities?

12•orange_puff•3d ago•8 comments

Ask HN: Exceptionally well-written research papers in CS/ML/AI?

5•b3rkus•4d ago•1 comments

Ask HN: What's the best realtime, local, TTS solution? Live call interpretation

6•Wright007•2d ago•2 comments

Tadpole the Language for Scraping 0.2.0 – Complex Control Flow, Stealth and More

6•zachperkitny•1d ago•2 comments

You've reached the end!