From c12126dd9768d213f0fb285f61299d79547d66f8 Mon Sep 17 00:00:00 2001 From: "J.-S. Caux" <J.S.Caux@uva.nl> Date: Sat, 4 May 2019 21:41:16 +0200 Subject: [PATCH] Add data: to IMG and SCRIPT sources --- SciPost_v1/settings/base.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/SciPost_v1/settings/base.py b/SciPost_v1/settings/base.py index b61abe64e..343f6b5f7 100644 --- a/SciPost_v1/settings/base.py +++ b/SciPost_v1/settings/base.py @@ -198,10 +198,11 @@ REFERRER_POLICY = 'same-origin' CSP_FONT_SRC = ("'self'", 'data:', 'fonts.gstatic.com', 'cdnjs.cloudflare.com', 'www.google.com', 'themes.googleusercontent.com') CSP_FRAME_SRC = ('www.google.com', 'player.vimeo.com') -CSP_IMG_SRC = ("'self'", 'ajax.googleapis.com', 'assets.crossref.org', +CSP_IMG_SRC = ("'self'", 'data:', 'ajax.googleapis.com', 'assets.crossref.org', 'licensebuttons.net', 'crossmark-cdn.crossref.org') -CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'", 'ajax.googleapis.com', 'cdnjs.cloudflare.com', - 'crossmark-cdn.crossref.org', 'www.recaptcha.net', 'www.gstatic.com', +CSP_SCRIPT_SRC = ("'self'", 'data:', "'unsafe-inline'", 'ajax.googleapis.com', + 'cdnjs.cloudflare.com', 'crossmark-cdn.crossref.org', + 'www.recaptcha.net', 'www.gstatic.com', 'code.jquery.com') CSP_STYLE_SRC = ("'self'", "'unsafe-inline'", 'ajax.googleapis.com', 'code.jquery.com', 'fonts.googleapis.com', 'cdnjs.cloudflare.com') -- GitLab