Recently I found out about browser policy package for Meteor from David Weldon (, which I found from this checklist made by Sacha
I use the Google analytics for iron router package ( as well and I keep getting the following error after trying many different options (I expected BrowserPolicy.content.allowInlineScripts(); to allow this):
Refused to load the script 'data:application/javascript;base64,dmFyIHVyY2hpblRyYWNrZXI9ZnVuY3Rpb24oKXt9…JVcmw6ZnVuY3Rpb24obyl7cmV0dXJuIG87fSxfdHJhY2tFdmVudDpmdW5jdGlvbigpe319fX07' because it violates the following Content Security Policy directive: "script-src 'self' http://* https://* http://* https://* http://* https://*".
anyone can give me more insight in this?
The URL in question is a Data URL, so one way to solve this is to add the following to your policy:
That's a pretty broad rule though. If you want to narrow it just to scripts you could do: