this is my header setting
<meta name="viewport" content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1, user-scalable=no" http-equiv="Access-Control-Allow-Origin" content="http://127.0.0.1:8000/">
<meta http-equiv="Content-Security-Policy" content="default-src "self" data: gap: https://ssl.gstatic.com;"unsafe-eval"; style-src "self" "unsafe-inline"; media-src *;connect-src *;script-src * "unsafe-inline";">
this is
in body.<script src="static/js/socket.js.js"></script>
the error report goes like this
:Unrecognized Content-Security-Policy directive ""unsafe-eval"".
:Uncaught EvalError: Refused to evaluate a string as JavaScript because "unsafe-eval" is not an allowed source of script in the following Content Security Policy directive: "script-src * "unsafe-inline"".