diff --git a/docker/ploughshares/app.py b/docker/ploughshares/app.py index ebc3a6e..6c3a3f9 100644 --- a/docker/ploughshares/app.py +++ b/docker/ploughshares/app.py @@ -165,6 +165,9 @@ def add_api_headers(response): # For UI routes, add additional security headers for header, value in additional_headers.items(): response.headers[header] = value + + # Make sure Cross-Origin-Embedder-Policy doesn't block resources + response.headers['Cross-Origin-Embedder-Policy'] = 'unsafe-none' return response