From 6ef32fa6474343873469fe7db5d4163e0f48dbba Mon Sep 17 00:00:00 2001
From: "J.-S. Caux" <J.S.Caux@uva.nl>
Date: Sat, 4 May 2019 15:32:54 +0200
Subject: [PATCH] Add Crossref as IMG_SRC

---
 SciPost_v1/settings/base.py | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/SciPost_v1/settings/base.py b/SciPost_v1/settings/base.py
index a6a812450..a0a90f8c5 100644
--- a/SciPost_v1/settings/base.py
+++ b/SciPost_v1/settings/base.py
@@ -198,7 +198,7 @@ X_FRAME_OPTIONS = 'DENY'
 REFERRER_POLICY = 'same-origin'
 CSP_FONT_SRC = ("'self'", 'fonts.gstatic.com', 'cdnjs.cloudflare.com')
 CSP_FRAME_SRC = ('www.google.com')
-CSP_IMG_SRC = ("'self'", 'licensebuttons.net', 'crossmark-cdn.crossref.org')
+CSP_IMG_SRC = ("'self'", 'assets.crossref.org', 'licensebuttons.net', 'crossmark-cdn.crossref.org')
 CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'", 'ajax.googleapis.com', 'cdnjs.cloudflare.com',
                   'crossmark-cdn.crossref.org', 'www.recaptcha.net', 'www.gstatic.com')
 CSP_STYLE_SRC = ("'self'", "'unsafe-inline'", 'ajax.googleapis.com',
-- 
GitLab