From: Tom Hughes Date: Thu, 17 May 2018 18:10:23 +0000 (+0100) Subject: Preserve schemes in security policy X-Git-Tag: live~3548 X-Git-Url: https://git.openstreetmap.org./rails.git/commitdiff_plain/5cd4aeb1aa08aaab2cb00a9de841783310790caa Preserve schemes in security policy --- diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index bb901e375..ba9aa496f 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -1,5 +1,6 @@ if defined?(CSP_REPORT_URL) csp_policy = { + :preserve_schemes => true, :default_src => %w['self'], :child_src => %w['self'], :connect_src => %w['self'],