@@ -220,7 +220,7 @@ void testHandleWithHttpsRequest() {
220220 handlerCaptor .getValue ().handle (null );
221221
222222 verify (responseHeaders ).add ("Strict-Transport-Security" , "max-age=63072000" );
223- verify (responseHeaders ).add ("Content-Security-Policy" , "default-src 'self'; img-src 'self'; style-src 'self' 'unsafe-hashes'; connect-src 'self'; script-src 'self' 'unsafe-eval'" );
223+ verify (responseHeaders ).add ("Content-Security-Policy" , "default-src 'self'; img-src 'self'; style-src 'self' 'unsafe-hashes'; connect-src 'self'; script-src 'self' 'unsafe-eval'; manifest-src 'self' " );
224224 verify (responseHeaders ).add ("X-Frame-Options" , "DENY" );
225225 verify (responseHeaders ).add ("X-Content-Type-Options" , "nosniff" );
226226 verify (responseHeaders ).add ("Referrer-Policy" , "same-origin" );
@@ -250,7 +250,7 @@ void testHandleWithHttpRequest() {
250250
251251 // Should not add HSTS for HTTP requests
252252 verify (responseHeaders , never ()).add ("Strict-Transport-Security" , "max-age=63072000" );
253- verify (responseHeaders ).add ("Content-Security-Policy" , "default-src 'self'; img-src 'self'; style-src 'self' 'unsafe-hashes'; connect-src 'self'; script-src 'self' 'unsafe-eval'" );
253+ verify (responseHeaders ).add ("Content-Security-Policy" , "default-src 'self'; img-src 'self'; style-src 'self' 'unsafe-hashes'; connect-src 'self'; script-src 'self' 'unsafe-eval'; manifest-src 'self' " );
254254 verify (responseHeaders ).add ("X-Frame-Options" , "DENY" );
255255 verify (responseHeaders ).add ("X-Content-Type-Options" , "nosniff" );
256256 verify (responseHeaders ).add ("Referrer-Policy" , "same-origin" );
0 commit comments