Merge branch 'master' into 3D-dev
This commit is contained in:
commit
0d6812cbb3
|
|
@ -107,7 +107,7 @@ public class CspFilter implements Filter {
|
||||||
String frameAncestors = allowIframe ? "'self'" : "'none'";
|
String frameAncestors = allowIframe ? "'self'" : "'none'";
|
||||||
|
|
||||||
cspPolicy = "default-src 'self'; " +
|
cspPolicy = "default-src 'self'; " +
|
||||||
"script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data:; " +
|
"script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: data:; " +
|
||||||
"style-src 'self' 'unsafe-inline' data: blob:; " +
|
"style-src 'self' 'unsafe-inline' data: blob:; " +
|
||||||
"img-src 'self' data: blob: https:; " +
|
"img-src 'self' data: blob: https:; " +
|
||||||
"font-src 'self' data: blob: https:; " +
|
"font-src 'self' data: blob: https:; " +
|
||||||
|
|
@ -124,12 +124,13 @@ public class CspFilter implements Filter {
|
||||||
String frameAncestors = allowIframe ? "'self'" : "'none'";
|
String frameAncestors = allowIframe ? "'self'" : "'none'";
|
||||||
|
|
||||||
cspPolicy = "default-src 'self'; " +
|
cspPolicy = "default-src 'self'; " +
|
||||||
"script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; " +
|
"script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: data:; " +
|
||||||
"style-src 'self' 'unsafe-inline' https:; " +
|
"style-src 'self' 'unsafe-inline' https:; " +
|
||||||
"img-src 'self' data: blob: https:; " +
|
"img-src 'self' data: blob: https:; " +
|
||||||
"font-src 'self' data: https:; " +
|
"font-src 'self' data: https:; " +
|
||||||
"connect-src 'self' https:; " +
|
"connect-src 'self' https:; " +
|
||||||
"frame-ancestors " + frameAncestors + "; " +
|
"frame-ancestors " + frameAncestors + "; " +
|
||||||
|
"worker-src 'self' blob: data:;"+
|
||||||
"form-action 'self'; " +
|
"form-action 'self'; " +
|
||||||
"object-src 'none'; " +
|
"object-src 'none'; " +
|
||||||
"base-uri 'self'; " +
|
"base-uri 'self'; " +
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue