Browse Source

Enhanded recommended CSP to include support for pdf web worker which loads stuff from blob: urls.

pull/156/merge
Simon Eisenmann 11 years ago
parent
commit
9ab17d1721
  1. 5
      server.conf.in

5
server.conf.in

@ -107,8 +107,9 @@ serverRealm = local @@ -107,8 +107,9 @@ serverRealm = local
; The currently recommended CSP is:
; default-src 'self';
; style-src 'self' 'unsafe-inline';
; img-src 'self' data:;
; connect-src 'self' wss://server:port/ws;
; img-src 'self' data: blob:;
; connect-src 'self' wss://server:port/ws blob:;
; font-src 'self' blob;
;contentSecurityPolicy =
; Content-Security-Policy-Report-Only HTTP response header value. Use this
; to test your CSP before putting it into production.

Loading…
Cancel
Save