# Help Resolving error: \[Report Only\] Refused to load the script

**URL:** <https://discuss.emberjs.com/t/help-resolving-error-report-only-refused-to-load-the-script/6902>\
**Category:** Ember CLI\
**Created:** [December 11, 2014, 7:56pm UTC](https://discuss.emberjs.com/t/help-resolving-error-report-only-refused-to-load-the-script/6902 "2014-12-11T19:56:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mithrilhall](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/mithrilhall/32/10074_2.png) [@Mithrilhall](https://discuss.emberjs.com/u/Mithrilhall)\
**Post date:** [December 11, 2014, 7:56pm UTC](https://discuss.emberjs.com/t/help-resolving-error-report-only-refused-to-load-the-script/6902/1 "2014-12-11T19:56:44Z")

</div>

I just created a new Ember-cli project and I keep getting two errors in Chrome’s console window.

```
[Report Only] Refused to load the script 'http://10.1.3.34:35729/livereload.js?snipver=1' because it violates the following Content Security Policy directive: "script-src 'self' 'localhost' 'unsafe-inline' 'unsafe-eval' localhost:35729".

```

and

```
[Report Only] Refused to connect to 'ws://10.1.3.34:35729/livereload' because it violates the following Content Security Policy directive: "connect-src 'self' 'localhost' ws://localhost:35729".

```

My contentSecurityPolicy in environment.js is:

```
contentSecurityPolicy: {
  'default-src': "'none' 'self'",
  'script-src': "'self' 'localhost' 'unsafe-inline' 'unsafe-eval'",
  'font-src': "'self'",
  'connect-src': "'self' 'localhost'",
  'style-src': "'self' 'unsafe-inline'",
}

```

---

<div class="post-metadata">

**Author:** ![smurgolo](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/smurgolo/32/9863_2.png) [@smurgolo](https://discuss.emberjs.com/u/smurgolo)\
**Post date:** [December 12, 2014, 12:45pm UTC](https://discuss.emberjs.com/t/help-resolving-error-report-only-refused-to-load-the-script/6902/2 "2014-12-12T12:45:19Z")

</div>

> [@Mithrilhall](#):
>
> Refused to load the script ‘[http://10.1.3.34:35729/livereload.js?snipver=1](http://10.1.3.34:35729/livereload.js?snipver=1)’ because it violates the following Content Security Policy directive: "script-src ‘self’

Hi! I believe you need to add the url 10.1.3.34 to your contentSecurityPolicy inside environment.js

i.e:

> contentSecurityPolicy: { ‘default-src’: “‘none’ ‘self’”,  
> ‘script-src’: “‘self’ ‘localhost’ ‘unsafe-inline’ ‘unsafe-eval’ 10.1.3.34:35729”, ‘font-src’: “‘self’”, ‘connect-src’: “‘self’ ‘localhost’”, ‘style-src’: “‘self’ ‘unsafe-inline’”, }

Take a look at this: [Content-Security-Policy (CSP) Header Quick Reference](http://content-security-policy.com/#source_list)
