diff --git a/atst/app.py b/atst/app.py index 7cc3574d..5d79d9b5 100644 --- a/atst/app.py +++ b/atst/app.py @@ -98,11 +98,15 @@ def set_default_headers(app): response.headers[ "Strict-Transport-Security" ] = "max-age=31536000; includeSubDomains" - response.headers["Content-Security-Policy"] = "default-src 'self'" response.headers["X-Content-Type-Options"] = "nosniff" response.headers["X-Frame-Options"] = "SAMEORIGIN" response.headers["X-XSS-Protection"] = "1; mode=block" + if ENV == 'dev': + response.headers["Content-Security-Policy"] = "default-src 'self' 'unsafe-eval'; connect-src *" + else: + response.headers["Content-Security-Policy"] = "default-src 'self' 'unsafe-eval'" + return response