From 3df34c8c4bf4f952fdbcd654a75c4cb28ac60b55 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Ricks?= Date: Thu, 25 Apr 2024 11:07:22 +0200 Subject: [PATCH] Change: Adjust content security policy to allow inline javascript Inline javascript is used by the build tool to detect older versions of browsers. Without adjusting the content security policy we aren't able to support older browsers. --- src/gsad.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/gsad.c b/src/gsad.c index 2ef955c7a..3ee667877 100644 --- a/src/gsad.c +++ b/src/gsad.c @@ -163,6 +163,7 @@ "base-uri 'none'; " \ "connect-src 'self'; " \ "script-src 'self'; " \ + "script-src-elem 'self' 'unsafe-inline';" \ "frame-ancestors 'none'; " \ "form-action 'self'; " \ "style-src-elem 'self' 'unsafe-inline'; " \