From 42de6296462d4f0998ebd332ab177528e649af25 Mon Sep 17 00:00:00 2001 From: James Cole Date: Thu, 9 Jan 2020 19:28:23 +0100 Subject: [PATCH] Fix #2981 --- app/Http/Middleware/SecureHeaders.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Http/Middleware/SecureHeaders.php b/app/Http/Middleware/SecureHeaders.php index fe2767717b..930f4af5e4 100644 --- a/app/Http/Middleware/SecureHeaders.php +++ b/app/Http/Middleware/SecureHeaders.php @@ -59,7 +59,7 @@ class SecureHeaders $csp = [ "default-src 'none'", "object-src 'self'", - sprintf("script-src 'nonce-%s' 'unsafe-inline' %s", $nonce, $google), + sprintf("script-src' 'nonce-%s' 'unsafe-inline' %s", $nonce, $google), "style-src 'self' 'unsafe-inline'", "base-uri 'self'", "font-src 'self' data:",