Content Security Policy
The overlay talks to Lyba's hosted API. If your app sends a strict Content Security Policy, the browser has to be allowed to reach Lyba, or review links will fail.
Allow Lyba's API origin
Add https://lyba.io to connect-src:
Content-Security-Policy: connect-src 'self' https://lyba.io;
On a preview, the widget's origin differs from Lyba's, so 'self' is not enough.
What a missing entry looks like
If https://lyba.io is missing, the overlay may appear but fail token validation. The toolbar loads but reports that the review link is invalid or has expired. In the browser console you will usually see a connect-src violation for https://lyba.io/api/v1/tokens-validate.
The review token itself is sent to Lyba as an X-Lyba-Token header by the overlay, not as a server-visible query string.
Recorded reviews
When the project offers recorded reviews, reviewers get a Record button in the toolbar. It records the tab (or, in Safari and Firefox, the browser window), the reviewer's voice, and an optional face bubble. Recordings upload straight to Lyba's storage. To allow this, a strict policy needs:
Content-Security-Policy: connect-src 'self' https://lyba.io https://*.r2.cloudflarestorage.com https://qahsylnsskeuoqogddld.supabase.co;
Permissions-Policy: display-capture=(self), microphone=(self), camera=(self)
If screen sharing is blocked (display-capture), the Record button doesn't appear. A blocked microphone or camera only removes that source from the recording. Recording isn't available in mobile browsers, but pins still work there.
Controlling recording from your app
The recording prop on <LybaReview /> takes false or { blockedPaths?, redactPaths? }, and defaults to {}:
falsehides the Record button.blockedPathspauses recording on those path prefixes (e.g.["/account/verify"]).redactPathskeeps the audio but blacks out the video.
Password and card fields are always blacked out while focused. See the <LybaReview /> reference for the full component API.