Compare commits

...

1 Commits

Author SHA1 Message Date
QuantumGhost 5818e8933a
Allow `data:` urls for `img-src` in CSP policies
This allows browser to display embedded images with `data:` urls.
9 months ago

@ -37,7 +37,7 @@ export function middleware(request: NextRequest) {
style-src 'self' 'unsafe-inline' ${scheme_source} ${whiteList};
worker-src 'self' ${scheme_source} ${csp} ${whiteList};
media-src 'self' ${scheme_source} ${csp} ${whiteList};
img-src *;
img-src http: https: data:;
font-src 'self';
object-src 'none';
base-uri 'self';

Loading…
Cancel
Save