Skip to content

Commit 39ae1d8

Browse files
[docs] Strengthen CSP rule
1 parent 55bea65 commit 39ae1d8

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

docs/public/_headers

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,4 +22,5 @@
2222
X-Content-Type-Options: nosniff
2323
X-XSS-Protection: 1; mode=block
2424
Referrer-Policy: strict-origin-when-cross-origin
25-
Content-Security-Policy: frame-ancestors 'self'
25+
# Copy https://github.com/oliviertassinari/mui-toolpad/blob/f4c4eb046b352e4fc00729c3bed605e671b040c4/packages/toolpad-studio/src/server/index.ts#L241
26+
Content-Security-Policy: default-src * data: mediastream: blob: filesystem: about: ws: wss: 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src-elem * data: blob: 'unsafe-inline'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors *;

0 commit comments

Comments
 (0)