Skip to content

Commit 691c39d

Browse files
committed
fix(discussable): added unsafe eval to script src
1 parent d467729 commit 691c39d

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

server.ts

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,9 @@ fastify.register(helmet, {
9595
contentSecurityPolicy: {
9696
directives: {
9797
'connect-src': ["'self'", 'sdk.openui5.org', sentryHost, dynatraceOrigin],
98-
'script-src': isLocalDev ? ["'self'", "'unsafe-inline'", dynatraceOrigin] : ["'self'", dynatraceOrigin],
98+
'script-src': isLocalDev
99+
? ["'self'", "'unsafe-inline'", "'unsafe-eval'", sentryHost, dynatraceOrigin]
100+
: ["'self'", "'unsafe-eval'", sentryHost, dynatraceOrigin],
99101
// @ts-ignore
100102
'frame-ancestors': [...fastify.config.FRAME_ANCESTORS.split(',')],
101103
},

0 commit comments

Comments
 (0)