update script-src CSP rules for iD

This commit is contained in:
Martin Raifer 2024-05-26 15:24:57 +02:00 committed by GitHub
parent affa9bbf15
commit 416fca5703
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -19,7 +19,6 @@ class SiteController < ApplicationController
content_security_policy(:only => :id) do |policy|
policy.connect_src("*")
policy.img_src("*", :blob)
policy.script_src(*policy.script_src, "dev.virtualearth.net", :unsafe_eval)
policy.style_src(*policy.style_src, :unsafe_inline)
end