reintroduce unsafe-eval CSP rule for iD

fixes https://github.com/openstreetmap/iD/issues/10265
This commit is contained in:
Martin Raifer 2024-05-29 11:26:08 +02:00 committed by GitHub
parent d3d0da0328
commit ed15352f56
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -19,6 +19,7 @@ class SiteController < ApplicationController
content_security_policy(:only => :id) do |policy|
policy.connect_src("*")
policy.img_src(*policy.img_src, "*", :blob)
policy.script_src(*policy.script_src, :unsafe_eval)
policy.style_src(*policy.style_src, :unsafe_inline)
end