From ed15352f56403caf0e0485474d872525a47d2d91 Mon Sep 17 00:00:00 2001 From: Martin Raifer Date: Wed, 29 May 2024 11:26:08 +0200 Subject: [PATCH] reintroduce unsafe-eval CSP rule for iD fixes https://github.com/openstreetmap/iD/issues/10265 --- app/controllers/site_controller.rb | 1 + 1 file changed, 1 insertion(+) diff --git a/app/controllers/site_controller.rb b/app/controllers/site_controller.rb index 8b742a585..15ffe58a2 100644 --- a/app/controllers/site_controller.rb +++ b/app/controllers/site_controller.rb @@ -19,6 +19,7 @@ class SiteController < ApplicationController content_security_policy(:only => :id) do |policy| policy.connect_src("*") policy.img_src(*policy.img_src, "*", :blob) + policy.script_src(*policy.script_src, :unsafe_eval) policy.style_src(*policy.style_src, :unsafe_inline) end -- 2.39.5