]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/application_controller.rb
Include data: when using allow_thirdparty_images CSP
[rails.git] / app / controllers / application_controller.rb
index 7ce804ced01af000ada0560ee4f27f99046618ac..fc90e0be7874652475307a695eefb2aece8990fb 100644 (file)
@@ -21,7 +21,7 @@ class ApplicationController < ActionController::Base
 
   def self.allow_thirdparty_images(**options)
     content_security_policy(options) do |policy|
-      policy.img_src("*")
+      policy.img_src("*", :data)
     end
   end