Remove strict CSP header for #4622

This commit is contained in:
James Cole 2021-04-09 06:05:27 +02:00
parent 075f951cfe
commit 1912e46113
No known key found for this signature in database
GPG Key ID: B5669F9493CDE38D

View File

@ -53,8 +53,6 @@ class SecureHeaders
$csp = [
"default-src 'none'",
"object-src 'none'",
"require-trusted-types-for 'script'",
//sprintf("script-src 'unsafe-inline' 'strict-dynamic' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
sprintf("script-src 'unsafe-eval' 'strict-dynamic' 'self' 'unsafe-inline' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
"style-src 'unsafe-inline' 'self'",
"base-uri 'self'",