We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 7f20d34 commit 8150065Copy full SHA for 8150065
webapp/src/EventListener/AddContentSecurityPolicyListener.php
@@ -17,7 +17,7 @@ public function __invoke(ResponseEvent $event): void
17
// the profiler requires 'unsafe-eval' for script-src 'self'.
18
$response = $event->getResponse();
19
$cspExtra = $this->profiler ? "'unsafe-eval'" : "";
20
- $csp = "default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' $cspExtra; img-src 'self' data:; worker-src 'self' blob:";
+ $csp = "default-src 'self' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline'; script-src 'self' https://cdn.jsdelivr.net 'unsafe-inline' $cspExtra; img-src 'self' data:; worker-src 'self' blob:";
21
$response->headers->set('Content-Security-Policy', $csp);
22
}
23
0 commit comments