fix: 放宽CSP策略,允许http和blob图片源
This commit is contained in:
+2
-2
@@ -35,8 +35,8 @@ app.use(helmet({
|
||||
scriptSrc: ["'self'", "'unsafe-inline'"],
|
||||
scriptSrcAttr: ["'unsafe-inline'"],
|
||||
styleSrc: ["'self'", "'unsafe-inline'", "https:"],
|
||||
imgSrc: ["'self'", "data:", "https:"],
|
||||
connectSrc: ["'self'", "https:"],
|
||||
imgSrc: ["'self'", "data:", "https:", "http:", "blob:"],
|
||||
connectSrc: ["'self'", "https:", "http:"],
|
||||
},
|
||||
},
|
||||
}));
|
||||
|
||||
Reference in New Issue
Block a user