Skip to content

Commit f2cfc78

Browse files
authored
Merge branch 'main' into mathjax
2 parents 7ff3deb + 8ba403e commit f2cfc78

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

webapp/src/EventListener/AddContentSecurityPolicyListener.php

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,10 @@ public function __invoke(ResponseEvent $event): void
1717
// the profiler requires 'unsafe-eval' for script-src 'self'.
1818
$response = $event->getResponse();
1919
$cspExtra = $this->profiler ? "'unsafe-eval'" : "";
20-
$csp = "font-src 'self' data:; default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' $cspExtra; img-src 'self' data:; worker-src 'self' blob:";
20+
$csp = "default-src 'self';";
21+
$csp .= "font-src 'self' data:; img-src 'self' data:;";
22+
$csp .= "style-src 'self' 'unsafe-inline'; worker-src 'self' blob:";
23+
$csp .= "script-src 'self' 'unsafe-inline' $cspExtra;";
2124
$response->headers->set('Content-Security-Policy', $csp);
2225
}
2326
}

0 commit comments

Comments
 (0)