I’ve been experimenting with writing some lightweight userscripts to explore Torn’s frontend behavior, purely for personal learning and UI enhancements (no automation or botting, of course).
I ran into an issue where certain pages seem to block userscripts entirely due to Content-Security-Policy (CSP) restrictions. Even when using Tampermonkey (Firefox) or wieldmonkey (Chrome), the browser blocks the script and throws errors like:
Content-Security-Policy: The page’s settings blocked an inline script (script-src-elem) from being executed because it violates the following directive: “script-src '*****-a2fc347df1ad1c6523a5285878bbdb72' '*****-
If I manually paste the exact same code into the DevTools console, it works just fine — so the problem isn’t the logic, just how the script is injected.