File tree Expand file tree Collapse file tree 1 file changed +4
-1
lines changed Expand file tree Collapse file tree 1 file changed +4
-1
lines changed Original file line number Diff line number Diff line change @@ -17,7 +17,10 @@ public function __invoke(ResponseEvent $event): void
1717 // the profiler requires 'unsafe-eval' for script-src 'self'.
1818 $ response = $ event ->getResponse ();
1919 $ cspExtra = $ this ->profiler ? "'unsafe-eval' " : "" ;
20- $ csp = "font-src 'self' data:; default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' $ cspExtra; img-src 'self' data:; worker-src 'self' blob: " ;
20+ $ csp = "default-src 'self'; " ;
21+ $ csp .= "font-src 'self' data:; img-src 'self' data:; " ;
22+ $ csp .= "style-src 'self' 'unsafe-inline'; worker-src 'self' blob: " ;
23+ $ csp .= "script-src 'self' 'unsafe-inline' $ cspExtra; " ;
2124 $ response ->headers ->set ('Content-Security-Policy ' , $ csp );
2225 }
2326}
You can’t perform that action at this time.
0 commit comments