From 15178f18b83d96073060d44e114a707919028546 Mon Sep 17 00:00:00 2001 From: Armand Philippot Date: Tue, 22 Feb 2022 15:47:53 +0100 Subject: chore: update CSP --- next.config.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) (limited to 'next.config.js') diff --git a/next.config.js b/next.config.js index 4b8214d..c324bb6 100644 --- a/next.config.js +++ b/next.config.js @@ -12,7 +12,7 @@ const contentSecurityPolicy = ` frame-src 'self'; img-src 'self' ${backendDomain} secure.gravatar.com data:; media-src 'self' data:; - script-src 'self' ${ackeeDomain} 'unsafe-inline'; + script-src 'self' ${ackeeDomain} 'unsafe-inline' data:; style-src 'self' 'unsafe-inline'; `; @@ -24,7 +24,8 @@ const contentSecurityPolicyDev = ` frame-src 'self'; img-src 'self' ${backendDomain} secure.gravatar.com data:; media-src 'self' data:; - script-src 'self' ${ackeeDomain} 'unsafe-inline' 'unsafe-eval'; + object-src 'self' data:; + script-src 'self' ${ackeeDomain} 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline'; `; -- cgit v1.2.3