From: Andy Allan Date: Wed, 29 May 2024 12:14:10 +0000 (+0100) Subject: Merge pull request #4856 from tyrasd/patch-2 X-Git-Tag: live~433 X-Git-Url: https://git.openstreetmap.org./rails.git/commitdiff_plain/9004c2d28d237d9c1dfe6ff707c2189731069593?hp=d3d0da03286d7bf9dc06027f8edb802a3102bb0b Merge pull request #4856 from tyrasd/patch-2 reintroduce unsafe-eval CSP rule for iD (Mapillary layer) --- diff --git a/app/controllers/site_controller.rb b/app/controllers/site_controller.rb index 8b742a585..15ffe58a2 100644 --- a/app/controllers/site_controller.rb +++ b/app/controllers/site_controller.rb @@ -19,6 +19,7 @@ class SiteController < ApplicationController content_security_policy(:only => :id) do |policy| policy.connect_src("*") policy.img_src(*policy.img_src, "*", :blob) + policy.script_src(*policy.script_src, :unsafe_eval) policy.style_src(*policy.style_src, :unsafe_inline) end