Merge pull request #505 from dod-ccpo/unsafe-inline-svg
Add ‘unsafe-inline’ to headers to fix rendering svgs
This commit is contained in:
commit
5fd2fc3558
@ -105,11 +105,11 @@ def set_default_headers(app): # pragma: no cover
|
||||
if ENV == "dev":
|
||||
response.headers[
|
||||
"Content-Security-Policy"
|
||||
] = "default-src 'self' 'unsafe-eval'; connect-src *"
|
||||
] = "default-src 'self' 'unsafe-eval' 'unsafe-inline'; connect-src *"
|
||||
else:
|
||||
response.headers[
|
||||
"Content-Security-Policy"
|
||||
] = "default-src 'self' 'unsafe-eval'"
|
||||
] = "default-src 'self' 'unsafe-eval' 'unsafe-inline'"
|
||||
|
||||
return response
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user