Skip to content

Commit e130f46

Browse files
fix: fix image csp for favicons
Signed-off-by: Henry Gressmann <[email protected]>
1 parent 20e9c9b commit e130f46

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

data/licenses-cargo.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

data/licenses-npm.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

src/web/mod.rs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ pub fn create_router(app: Liwan, events: Sender<Event>) -> impl IntoEndpoint {
6262
.appending("X-Frame-Options", "DENY")
6363
.appending("X-Content-Type-Options", "nosniff")
6464
.appending("X-XSS-Protection", "1; mode=block")
65-
.appending("Content-Security-Policy", "default-src 'self' data: 'unsafe-inline'")
65+
.appending("Content-Security-Policy", "default-src 'self' data: 'unsafe-inline'; img-src https://*")
6666
.appending("Referrer-Policy", "same-origin")
6767
.appending("Permissions-Policy", "geolocation=(), microphone=(), camera=()");
6868

0 commit comments

Comments
 (0)