From: Martin Raifer Date: Wed, 29 May 2024 09:26:08 +0000 (+0200) Subject: reintroduce unsafe-eval CSP rule for iD X-Git-Tag: live~542^2 X-Git-Url: https://git.openstreetmap.org./rails.git/commitdiff_plain/ed15352f56403caf0e0485474d872525a47d2d91 reintroduce unsafe-eval CSP rule for iD fixes https://github.com/openstreetmap/iD/issues/10265 --- diff --git a/app/controllers/site_controller.rb b/app/controllers/site_controller.rb index 8b742a585..15ffe58a2 100644 --- a/app/controllers/site_controller.rb +++ b/app/controllers/site_controller.rb @@ -19,6 +19,7 @@ class SiteController < ApplicationController content_security_policy(:only => :id) do |policy| policy.connect_src("*") policy.img_src(*policy.img_src, "*", :blob) + policy.script_src(*policy.script_src, :unsafe_eval) policy.style_src(*policy.style_src, :unsafe_inline) end