Skip to content

Commit f21f403

Browse files
committed
Merge branch 'small-security-settings-fixes' into add-cors
2 parents 0a6d83e + 380b885 commit f21f403

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

server.ts

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -116,8 +116,9 @@ fastify.register(helmet, {
116116
contentSecurityPolicy: {
117117
directives: {
118118
defaultSrc: ["'self'"],
119+
// styleSrc: unsafe-inline is needed for our styling
119120
styleSrc: ["'self'", "'unsafe-inline'"],
120-
imgSrc: ["'self'", 'data:', 'https:'],
121+
imgSrc: ["'self'", 'data:'],
121122
'connect-src': ["'self'", 'sdk.openui5.org', sentryHost, dynatraceOrigin],
122123
'script-src': isLocalDev
123124
? ["'self'", "'unsafe-inline'", "'unsafe-eval'", sentryHost, dynatraceOrigin]

vite.config.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ export default defineConfig({
3535
},
3636

3737
build: {
38-
sourcemap: process.env.NODE_ENV !== 'production',
38+
sourcemap: true, // crucial for sentry
3939
target: 'esnext', // Support top-level await
4040
},
4141
});

0 commit comments

Comments
 (0)