From 53233c80a81a42cf37a5cdf917fe8dce542558a6 Mon Sep 17 00:00:00 2001 From: yanu <10122431+ynwd@users.noreply.github.com> Date: Sun, 18 Aug 2024 11:46:07 +0700 Subject: [PATCH] csp for style and img adjustment --- http/server/render.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/http/server/render.ts b/http/server/render.ts index 14d8f3152..9c594b805 100644 --- a/http/server/render.ts +++ b/http/server/render.ts @@ -130,7 +130,7 @@ es.onmessage = function(e) { "content-type": "text/html", "x-request-id": new Date().getTime().toString(), "Content-Security-Policy": - `default-src 'self'; script-src 'self' 'nonce-${nonce}' 'strict-dynamic'; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self'; frame-src 'self'`, + `script-src 'self' 'nonce-${nonce}' 'strict-dynamic';`, }); const children = typeof p.component == "function" ? h(p.component as FunctionComponent, { data, nonce })