Some websites don't allow that resources from a different domain than that of itself are being loaded. If you want your website to have Mopinion feedback forms it can be necessary to add HTTP headers to allow Cross-Origin Resource Sharing (CORS).  For more information on Cross-Origin Resource Sharing please see   https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS.

Below you will find the domains Mopinion uses and an example of how this should be defined in Nginx.

If you are on app.mopinion.com

type domains extra
script-src https://deploy.mopinion.com https://collect.mopinion.com https://app.mopinion.com 'unsafe-eval' 'unsafe-inline'
style-src https://app.mopinion.com fonts.mopinion.com
frame-src https://app.mopinion.com
connect-src http://pastease.mopinion.com
font-src 'self' data: gstatic.mopinion.com

 

Example in Nginx:

add_header Content-Security-Policy "script-src 'self' 'unsafe-eval' 'unsafe-inline' https://deploy.mopinion.com https://collect.mopinion.com https://app.mopinion.com; style-src 'self' https://app.mopinion.com fonts.mopinion.com; frame-src https://app.mopinion.com; connect-src http://pastease.mopinion.com; font-src 'self' data: gstatic.mopinion.com;";

 

If you are on {YOUR_COMPANY}.mopinion.com. (replace the value {YOUR_COMPANY} by the domain name Mopinion provided you)

type domains extra
script-src https://deploy.mopinion.com https://collect.mopinion.com https://{YOUR_COMPANY}.mopinion.com 'unsafe-eval' 'unsafe-inline'
style-src https://{YOUR_COMPANY}.mopinion.com fonts.mopinion.com
frame-src https://{YOUR_COMPANY}.mopinion.com
connect-src http://pastease.mopinion.com
font-src 'self' data: gstatic.mopinion.com

 

Example in Nginx:

add_header Content-Security-Policy "script-src 'self' 'unsafe-eval' 'unsafe-inline' https://deploy.mopinion.com https://collect.mopinion.com https://{YOUR_COMPANY}.mopinion.com; style-src 'self' https://{YOUR_COMPANY}.mopinion.com fonts.mopinion.com; frame-src https://{YOUR_COMPANY}.mopinion.com; connect-src http://pastease.mopinion.com; font-src 'self' data:; gstatic.mopinion.com";