diff --git a/docker/ploughshares/app.py b/docker/ploughshares/app.py index 6c3a3f9..997630f 100644 --- a/docker/ploughshares/app.py +++ b/docker/ploughshares/app.py @@ -59,9 +59,9 @@ if CSP_CUSTOM_CSS_HASH: csp = { 'default-src': ["'self'", "'unsafe-inline'", "'unsafe-eval'", "data:", "blob:"], 'script-src': ["'self'", "'unsafe-inline'", "'unsafe-eval'"], - 'style-src': ["'self'", "'unsafe-inline'"], + 'style-src': ["'self'", "'unsafe-inline'", "cdn.jsdelivr.net"], 'img-src': ["'self'", "data:", "blob:"], - 'font-src': ["'self'", "data:"], + 'font-src': ["'self'", "data:", "cdn.jsdelivr.net"], 'connect-src': ["'self'", "*"], 'manifest-src': "'self'", 'object-src': "'none'", # Still explicitly disallow objects diff --git a/docker/ploughshares/templates/base.html b/docker/ploughshares/templates/base.html index 4d98573..98e5a03 100644 --- a/docker/ploughshares/templates/base.html +++ b/docker/ploughshares/templates/base.html @@ -6,6 +6,7 @@ {% block title %}Project Ploughshares - Transaction Management System{% endblock %} +