Fix the CSP offline feature. (#10923)
This commit is contained in:
@@ -174,7 +174,7 @@ def create_block_external_middleware():
|
|||||||
else:
|
else:
|
||||||
response = await handler(request)
|
response = await handler(request)
|
||||||
|
|
||||||
response.headers['Content-Security-Policy'] = "default-src 'self'; script-src 'self' 'unsafe-inline' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self'; frame-src 'self'; object-src 'self';"
|
response.headers['Content-Security-Policy'] = "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self'; frame-src 'self'; object-src 'self';"
|
||||||
return response
|
return response
|
||||||
|
|
||||||
return block_external_middleware
|
return block_external_middleware
|
||||||
|
|||||||
Reference in New Issue
Block a user