Skip to content

Commit 7906d41

Browse files
committed
Relax <iframe>'s fetch CSP since it is not possible to know all origins that extensions want to connect to
1 parent 102590f commit 7906d41

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/vs/workbench/services/extensions/browser/webWorkerExtensionHost.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ export class WebWorkerExtensionHost extends Disposable implements IExtensionHost
102102
const html = `<!DOCTYPE html>
103103
<html>
104104
<head>
105-
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'unsafe-eval' ${sourcesOrigin} https://*.gallerycdn.vsassets.io '${WEB_WORKER_IFRAME.sha}'; worker-src data:; connect-src ${sourcesOrigin} https://*.gallerycdn.vsassets.io" />
105+
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'unsafe-eval' ${sourcesOrigin} https://*.gallerycdn.vsassets.io '${WEB_WORKER_IFRAME.sha}'; worker-src data:; connect-src *" />
106106
<meta id="vscode-worker-src" data-value="${escapeAttribute(workerSrc)}" />
107107
<meta id="vscode-web-worker-ext-host-id" data-value="${escapeAttribute(vscodeWebWorkerExtHostId)}" />
108108
</head>

0 commit comments

Comments
 (0)