Skip to content

Commit

Permalink
portal: allow blob as img-src in CSP
Browse files Browse the repository at this point in the history
  • Loading branch information
danigargar committed Sep 2, 2024
1 parent e41bcc0 commit 75b7786
Showing 1 changed file with 4 additions and 4 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ Alias /platform /opt/irontec/ivozprovider/web/portal/platform/dist
</Limit>

Header set X-Frame-Options SAMEORIGIN
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:;"
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:; img-src 'self' data: blob:"

<IfModule mod_rewrite.c>
RewriteEngine On
Expand All @@ -64,7 +64,7 @@ Alias /brand /opt/irontec/ivozprovider/web/portal/brand/dist
</Limit>

Header set X-Frame-Options SAMEORIGIN
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:;"
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:; img-src 'self' data: blob:"

<IfModule mod_rewrite.c>
RewriteEngine On
Expand All @@ -90,7 +90,7 @@ Alias /client /opt/irontec/ivozprovider/web/portal/client/dist
</Limit>

Header set X-Frame-Options SAMEORIGIN
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:;"
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:; img-src 'self' data: blob:"

<IfModule mod_rewrite.c>
RewriteEngine On
Expand All @@ -117,7 +117,7 @@ Alias /user /opt/irontec/ivozprovider/web/portal/user/dist
</Limit>

Header set X-Frame-Options SAMEORIGIN
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:;"
Header set Content-Security-Policy "default-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' *.googleapis.com 'unsafe-inline'; font-src 'self' *.googleapis.com *.gstatic.com; media-src 'self' blob:; img-src 'self' data: blob:"

<IfModule mod_rewrite.c>
RewriteEngine On
Expand Down

0 comments on commit 75b7786

Please sign in to comment.