forked from treehouse/mastodon
config: CSP: add unsafe-eval for scripts
parent
152f5c7983
commit
d0e2d7df37
|
@ -31,7 +31,7 @@ if Rails.env.production?
|
||||||
p.base_uri :none
|
p.base_uri :none
|
||||||
p.default_src :none
|
p.default_src :none
|
||||||
p.frame_ancestors :none
|
p.frame_ancestors :none
|
||||||
p.script_src :self, assets_host
|
p.script_src :self, assets_host, :unsafe_eval
|
||||||
p.font_src :self, assets_host
|
p.font_src :self, assets_host
|
||||||
p.img_src :self, :data, :blob, *data_hosts
|
p.img_src :self, :data, :blob, *data_hosts
|
||||||
p.style_src :self, assets_host
|
p.style_src :self, assets_host
|
||||||
|
|
Loading…
Reference in New Issue