Proxy violates Synology DSM CSP

I’ve setup Cloudflare Origin Certificate on my Synology NAS, confirmed in Chrome by accessing the IP directly. When turning on Cloudflare proxy (orange cloud) the DSM page is blank:

Refused to load the script ‘’ because it violates the following Content Security Policy directive: “script-src ‘self’ ‘unsafe-eval’ data: blob: https://*”. Note that ‘script-src-elem’ was not explicitly set, so ‘script-src’ is used as a fallback.

Any idea how to add the sources or remove Cloudflare injected scripts?

That’s the Rocket Loader feature from the Speed → Optimization section of

Thanks for quick reply! Really turning Rocket off allows me to access NAS web page.

