extend content security policy to allow data images
This commit is contained in:
parent
b68af58321
commit
a0d216c61d
|
@ -314,7 +314,7 @@ return [
|
||||||
'X-Content-Type-Options' => 'nosniff',
|
'X-Content-Type-Options' => 'nosniff',
|
||||||
'X-Frame-Options' => 'sameorigin',
|
'X-Frame-Options' => 'sameorigin',
|
||||||
'Referrer-Policy' => 'strict-origin-when-cross-origin',
|
'Referrer-Policy' => 'strict-origin-when-cross-origin',
|
||||||
'Content-Security-Policy' => 'default-src \'self\' \'unsafe-inline\' \'unsafe-eval\'',
|
'Content-Security-Policy' => 'default-src \'self\' \'unsafe-inline\' \'unsafe-eval\'; img-src \'self\' data:;',
|
||||||
'X-XSS-Protection' => '1; mode=block',
|
'X-XSS-Protection' => '1; mode=block',
|
||||||
'Feature-Policy' => 'autoplay \'none\'',
|
'Feature-Policy' => 'autoplay \'none\'',
|
||||||
//'Strict-Transport-Security' => 'max-age=7776000',
|
//'Strict-Transport-Security' => 'max-age=7776000',
|
||||||
|
|
Loading…
Reference in New Issue