patchCSP option: allow @import
from any URL (#1297)
This commit is contained in:
parent
6650a37194
commit
6e591b0d52
|
@ -112,8 +112,8 @@
|
||||||
// Allow style assets
|
// Allow style assets
|
||||||
patchCspSrc(src, 'img-src', 'data:', '*');
|
patchCspSrc(src, 'img-src', 'data:', '*');
|
||||||
patchCspSrc(src, 'font-src', 'data:', '*');
|
patchCspSrc(src, 'font-src', 'data:', '*');
|
||||||
// Allow our DOM styles
|
// Allow our DOM styles, allow @import from any URL
|
||||||
patchCspSrc(src, 'style-src', "'unsafe-inline'");
|
patchCspSrc(src, 'style-src', "'unsafe-inline'", '*');
|
||||||
// Allow our XHR cookies in CSP sandbox (known case: raw github urls)
|
// Allow our XHR cookies in CSP sandbox (known case: raw github urls)
|
||||||
if (src.sandbox && !src.sandbox.includes('allow-same-origin')) {
|
if (src.sandbox && !src.sandbox.includes('allow-same-origin')) {
|
||||||
src.sandbox.push('allow-same-origin');
|
src.sandbox.push('allow-same-origin');
|
||||||
|
|
Loading…
Reference in New Issue
Block a user