From d2c70ee7463f56dc69c2ec8ac6625a9226264267 Mon Sep 17 00:00:00 2001 From: Leopere Date: Fri, 7 Mar 2025 19:01:56 -0500 Subject: [PATCH] Update Content Security Policy to allow data fonts and blob workers --- docker/showerloop/Caddyfile.default.template | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docker/showerloop/Caddyfile.default.template b/docker/showerloop/Caddyfile.default.template index f62e947..079599e 100644 --- a/docker/showerloop/Caddyfile.default.template +++ b/docker/showerloop/Caddyfile.default.template @@ -49,7 +49,7 @@ X-Frame-Options "SAMEORIGIN" # Update CSP to allow media content, scripts, and blob URLs - Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self'; connect-src 'self'; frame-ancestors 'none'; block-all-mixed-content;" + Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none'; worker-src 'self' blob:" # Remove Server header -Server