Skip to content

Commit fc4df94

Browse files
fix: fix image csp for svg's
Signed-off-by: Henry Gressmann <[email protected]>
1 parent e130f46 commit fc4df94

File tree

2 files changed

+5
-2
lines changed

2 files changed

+5
-2
lines changed

data/licenses-cargo.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

src/web/mod.rs

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ pub fn create_router(app: Liwan, events: Sender<Event>) -> impl IntoEndpoint {
6262
.appending("X-Frame-Options", "DENY")
6363
.appending("X-Content-Type-Options", "nosniff")
6464
.appending("X-XSS-Protection", "1; mode=block")
65-
.appending("Content-Security-Policy", "default-src 'self' data: 'unsafe-inline'; img-src https://*")
65+
.appending(
66+
"Content-Security-Policy",
67+
"default-src 'self' data: 'unsafe-inline'; img-src 'self' data: https://*",
68+
)
6669
.appending("Referrer-Policy", "same-origin")
6770
.appending("Permissions-Policy", "geolocation=(), microphone=(), camera=()");
6871

0 commit comments

Comments
 (0)