Docs menu
Docs/Lyba RX

Content Security Policy

The overlay talks to Lyba's hosted API. If your app sends a strict Content Security Policy, the browser has to be allowed to reach Lyba, or review links will fail.

Allow Lyba's API origin

Add https://lyba.io to connect-src:

text
Content-Security-Policy: connect-src 'self' https://lyba.io;

On a preview, the widget's origin differs from Lyba's, so 'self' is not enough.

What a missing entry looks like

If https://lyba.io is missing, the overlay may appear but fail token validation. The toolbar loads but reports that the review link is invalid or has expired. In the browser console you will usually see a connect-src violation for https://lyba.io/api/v1/tokens-validate.

The review token itself is sent to Lyba as an X-Lyba-Token header by the overlay, not as a server-visible query string.

Recorded reviews

When the project offers recorded reviews, reviewers get a Record button in the toolbar. It records the tab (or, in Safari and Firefox, the browser window), the reviewer's voice, and an optional face bubble. Recordings upload straight to Lyba's storage. To allow this, a strict policy needs:

text
Content-Security-Policy: connect-src 'self' https://lyba.io https://*.r2.cloudflarestorage.com https://qahsylnsskeuoqogddld.supabase.co;
Permissions-Policy: display-capture=(self), microphone=(self), camera=(self)

If screen sharing is blocked (display-capture), the Record button doesn't appear. A blocked microphone or camera only removes that source from the recording. Recording isn't available in mobile browsers, but pins still work there.

Controlling recording from your app

The recording prop on <LybaReview /> takes false or { blockedPaths?, redactPaths? }, and defaults to {}:

  • false hides the Record button.
  • blockedPaths pauses recording on those path prefixes (e.g. ["/account/verify"]).
  • redactPaths keeps the audio but blacks out the video.

Password and card fields are always blacked out while focused. See the <LybaReview /> reference for the full component API.