From 67ebf9045c20cedcbe75c3bd5cdf57c6d5712398 Mon Sep 17 00:00:00 2001 From: Jeroen De Meerleer Date: Wed, 2 Feb 2022 13:00:17 +0100 Subject: [PATCH] BUGFIX: CSP did not allow runnow --- lib/Framework/Router.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/Framework/Router.php b/lib/Framework/Router.php index ca55721..c19c73b 100644 --- a/lib/Framework/Router.php +++ b/lib/Framework/Router.php @@ -34,7 +34,7 @@ class Router if ($response instanceof Response) { $response->headers->add([ - "Content-Security-Policy" => "default-src 'none'; font-src 'self'; style-src 'self'; script-src 'self'; img-src 'self' data:; form-action 'self'; require-trusted-types-for 'script'" + "Content-Security-Policy" => "default-src 'none'; font-src 'self'; style-src 'self'; script-src 'self'; connect-src 'self'; img-src 'self' data:; form-action 'self'; require-trusted-types-for 'script'; frame-ancestors 'none'; base-uri 'none'" ]); return $response; } else {