Fix CSP connect-src to allow cdn.jsdelivr.net
All checks were successful
Build and Push Docker Image / build-and-push (push) Successful in 58s
All checks were successful
Build and Push Docker Image / build-and-push (push) Successful in 58s
Allow connections to cdn.jsdelivr.net for Chart.js resources. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
@@ -70,7 +70,7 @@ class SecurityHeadersMiddleware(BaseHTTPMiddleware):
|
|||||||
"style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; "
|
"style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; "
|
||||||
"font-src 'self' https://fonts.gstatic.com; "
|
"font-src 'self' https://fonts.gstatic.com; "
|
||||||
"img-src 'self' data:; "
|
"img-src 'self' data:; "
|
||||||
"connect-src 'self'; "
|
"connect-src 'self' https://cdn.jsdelivr.net; "
|
||||||
"frame-ancestors 'none'; "
|
"frame-ancestors 'none'; "
|
||||||
"base-uri 'self'; "
|
"base-uri 'self'; "
|
||||||
"form-action 'self';"
|
"form-action 'self';"
|
||||||
|
|||||||
Reference in New Issue
Block a user