fix: CSP img-src放宽为*通配符

This commit is contained in:
Developer
2026-05-17 13:10:44 +08:00
parent c3b309413e
commit b31835a74d
+1 -1
View File
@@ -35,7 +35,7 @@ app.use(helmet({
scriptSrc: ["'self'", "'unsafe-inline'"], scriptSrc: ["'self'", "'unsafe-inline'"],
scriptSrcAttr: ["'unsafe-inline'"], scriptSrcAttr: ["'unsafe-inline'"],
styleSrc: ["'self'", "'unsafe-inline'", "https:"], styleSrc: ["'self'", "'unsafe-inline'", "https:"],
imgSrc: ["'self'", "data:", "https:", "http:", "blob:"], imgSrc: ["*", "data:", "blob:"],
connectSrc: ["'self'", "https:", "http:"], connectSrc: ["'self'", "https:", "http:"],
}, },
}, },