Maintenance: Remove obsolete CSP header unsafe_inline configuration exception.
This commit is contained in:
parent
ce4ca035d6
commit
0faf0a0759
1 changed files with 1 additions and 1 deletions
|
@ -37,7 +37,7 @@ Rails.application.config.content_security_policy do |policy|
|
||||||
policy.font_src :self, :data
|
policy.font_src :self, :data
|
||||||
policy.img_src '*', :data
|
policy.img_src '*', :data
|
||||||
policy.object_src :none
|
policy.object_src :none
|
||||||
policy.script_src :self, :unsafe_eval, :unsafe_inline, :strict_dynamic
|
policy.script_src :self, :unsafe_eval, :strict_dynamic
|
||||||
policy.style_src :self, :unsafe_inline
|
policy.style_src :self, :unsafe_inline
|
||||||
policy.frame_src 'www.youtube.com', 'player.vimeo.com'
|
policy.frame_src 'www.youtube.com', 'player.vimeo.com'
|
||||||
end
|
end
|
||||||
|
|
Loading…
Reference in a new issue