Healing Arts / E-Commerce
The Problem
Prismatic Flowers had been operating with zero confirmed Stripe orders for 30 days. The owner (Reverend Michael Allison) believed customers were declining the cart at checkout. Real cause: AppWT's default Security Headers CSP omitted https://js.stripe.com from the script-src directive AND set Permissions-Policy payment=(), which silently blocked Stripe.js from loading at all. Browsers showed a checkout button but it never connected to Stripe — orders silently disappeared.
The Approach
- Diagnosed by viewing the live checkout in browser DevTools — Console showed "Refused to load https://js.stripe.com/v3/" CSP violation
- Audited 107 .htaccess files across the AppWT-managed network — 104 had the same broken CSP
- Patched all 104 files with corrected CSP (added js.stripe.com to script-src + connect-src + frame-src; changed Permissions-Policy payment=() to payment=(self "https://js.stripe.com"))
- Verified Stripe.js loads cleanly on all 104 sites; ran 48-viewport puppeteer pass to confirm no rendering regressions
- Backed up all original .htaccess files to .bak-csp-stripe-20260427 for safe rollback
The Result
Within 48 hours of the fix, Prismatic Flowers received its first $536 order (confirmed in maillog 2026-05-01). The network-wide patch script (/root/deploy-csp-network.sh) was updated so future site deploys inherit the fix. Memory pin saved at feedback_appwt_csp_blocks_stripe.md so the bug never recurs.
Measurable Outcomes
Have a similar problem?
Free 30-minute consultation. No obligation. We diagnose first, recommend second.
Talk to AppWT →