DEV: Remove blob: workers from CSP (#10440)

Ace editor is reconfigured to load workers directly from their JS URL. Workers must be on the same origin as the site, so they will not use the CDN.
This commit is contained in:
David Taylor
2020-08-14 18:15:30 +01:00
committed by GitHub
parent f52927cd33
commit 8ac85f54fb
3 changed files with 5 additions and 3 deletions

View File

@@ -63,8 +63,7 @@ class ContentSecurityPolicy
def worker_src
[
"'self'",
"blob:",
"'self'", # For service worker
*script_assets(worker: true)
]
end