From 75207fe0d33670bdac72a486629b04ff620c0ec5 Mon Sep 17 00:00:00 2001 From: "J.-S. Caux" <J.S.Caux@uva.nl> Date: Sat, 4 May 2019 16:09:03 +0200 Subject: [PATCH] Allow vimeo player in iframe --- SciPost_v1/settings/base.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SciPost_v1/settings/base.py b/SciPost_v1/settings/base.py index a0a90f8c5..1f8e67b20 100644 --- a/SciPost_v1/settings/base.py +++ b/SciPost_v1/settings/base.py @@ -197,7 +197,7 @@ SECURE_CONTENT_TYPE_NOSNIFF = True X_FRAME_OPTIONS = 'DENY' REFERRER_POLICY = 'same-origin' CSP_FONT_SRC = ("'self'", 'fonts.gstatic.com', 'cdnjs.cloudflare.com') -CSP_FRAME_SRC = ('www.google.com') +CSP_FRAME_SRC = ('www.google.com', 'player.vimeo.com') CSP_IMG_SRC = ("'self'", 'assets.crossref.org', 'licensebuttons.net', 'crossmark-cdn.crossref.org') CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'", 'ajax.googleapis.com', 'cdnjs.cloudflare.com', 'crossmark-cdn.crossref.org', 'www.recaptcha.net', 'www.gstatic.com') -- GitLab