Skip to content

Commit ecaa3a4

Browse files
committed
Merge branch 'feature-DATAAPI-41_csp-nonce-support' into release-3.8.0
2 parents be201fd + 6eb099a commit ecaa3a4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

handlers/rest-apis/data/v1/docs/Swagger.cfc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ component {
2222
args.favicon = event.buildLink( systemStaticAsset="/extension/preside-ext-data-api/assets/favicon-32x32.png" );
2323
}
2424

25-
event?.setContentSecurityPolicy( "default-src 'self'; style-src 'self' 'unsafe-inline' 'nonce-#event?.getRequestNonce()#'" );
25+
event?.setContentSecurityPolicy( "default-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; worker-src blob:;" );
2626

2727
restResponse.setData( Trim( renderView( view="/swaggerLayout", args=args ) ) );
2828
restResponse.setMimeType( "text/html" );

0 commit comments

Comments
 (0)