From: Tom Hughes Date: Wed, 29 May 2024 16:52:40 +0000 (+0100) Subject: Merge remote-tracking branch 'upstream/pull/4849' X-Git-Tag: live~721 X-Git-Url: https://git.openstreetmap.org./rails.git/commitdiff_plain/b5dd8c19b9b9c4bbb09e07f6c4898ebb52b06b39?hp=1d35daa0b5867e3834db5b6a2056819dafbe167a Merge remote-tracking branch 'upstream/pull/4849' --- diff --git a/app/controllers/site_controller.rb b/app/controllers/site_controller.rb index 8b742a585..15ffe58a2 100644 --- a/app/controllers/site_controller.rb +++ b/app/controllers/site_controller.rb @@ -19,6 +19,7 @@ class SiteController < ApplicationController content_security_policy(:only => :id) do |policy| policy.connect_src("*") policy.img_src(*policy.img_src, "*", :blob) + policy.script_src(*policy.script_src, :unsafe_eval) policy.style_src(*policy.style_src, :unsafe_inline) end