mirror of
https://github.com/discourse/discourse.git
synced 2025-02-25 18:55:32 -06:00
DEV: Remove blob: workers from CSP (#10440)
Ace editor is reconfigured to load workers directly from their JS URL. Workers must be on the same origin as the site, so they will not use the CDN.
This commit is contained in:
@@ -63,8 +63,7 @@ class ContentSecurityPolicy
|
||||
|
||||
def worker_src
|
||||
[
|
||||
"'self'",
|
||||
"blob:",
|
||||
"'self'", # For service worker
|
||||
*script_assets(worker: true)
|
||||
]
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user