fix: 放宽CSP策略,允许http和blob图片源
This commit is contained in:
+2
-2
@@ -35,8 +35,8 @@ app.use(helmet({
|
|||||||
scriptSrc: ["'self'", "'unsafe-inline'"],
|
scriptSrc: ["'self'", "'unsafe-inline'"],
|
||||||
scriptSrcAttr: ["'unsafe-inline'"],
|
scriptSrcAttr: ["'unsafe-inline'"],
|
||||||
styleSrc: ["'self'", "'unsafe-inline'", "https:"],
|
styleSrc: ["'self'", "'unsafe-inline'", "https:"],
|
||||||
imgSrc: ["'self'", "data:", "https:"],
|
imgSrc: ["'self'", "data:", "https:", "http:", "blob:"],
|
||||||
connectSrc: ["'self'", "https:"],
|
connectSrc: ["'self'", "https:", "http:"],
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
}));
|
}));
|
||||||
|
|||||||
Reference in New Issue
Block a user