fix: CSP for client-side editor uploads
This commit is contained in:
@ -122,6 +122,11 @@ app.use(
|
|||||||
styleSrc: ["'self'", "'unsafe-inline'", 'github.githubassets.com'],
|
styleSrc: ["'self'", "'unsafe-inline'", 'github.githubassets.com'],
|
||||||
imgSrc: ['*', 'data:', 'blob:'],
|
imgSrc: ['*', 'data:', 'blob:'],
|
||||||
frameSrc: ['*'],
|
frameSrc: ['*'],
|
||||||
|
connectSrc: [
|
||||||
|
"'self'",
|
||||||
|
process.env.AWS_S3_UPLOAD_BUCKET_URL,
|
||||||
|
'www.google-analytics.com',
|
||||||
|
],
|
||||||
},
|
},
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
Reference in New Issue
Block a user