aboutsummaryrefslogtreecommitdiffstats
path: root/subprojects/language-web
diff options
context:
space:
mode:
Diffstat (limited to 'subprojects/language-web')
-rw-r--r--subprojects/language-web/src/main/java/tools/refinery/language/web/SecurityHeadersFilter.java4
1 files changed, 2 insertions, 2 deletions
diff --git a/subprojects/language-web/src/main/java/tools/refinery/language/web/SecurityHeadersFilter.java b/subprojects/language-web/src/main/java/tools/refinery/language/web/SecurityHeadersFilter.java
index cc87917f..19eeeff3 100644
--- a/subprojects/language-web/src/main/java/tools/refinery/language/web/SecurityHeadersFilter.java
+++ b/subprojects/language-web/src/main/java/tools/refinery/language/web/SecurityHeadersFilter.java
@@ -20,8 +20,8 @@ public class SecurityHeadersFilter implements Filter {
20 // CodeMirror needs inline styles, see e.g., 20 // CodeMirror needs inline styles, see e.g.,
21 // https://discuss.codemirror.net/t/inline-styles-and-content-security-policy/1311/2 21 // https://discuss.codemirror.net/t/inline-styles-and-content-security-policy/1311/2
22 "style-src 'self' 'unsafe-inline'; " + 22 "style-src 'self' 'unsafe-inline'; " +
23 // Use 'data:' for displaying inline SVG backgrounds. 23 // Use 'data:' for displaying inline SVG backgrounds and blob for rendering SVG.
24 "img-src 'self' data:; " + 24 "img-src 'self' data: blob:; " +
25 "font-src 'self'; " + 25 "font-src 'self'; " +
26 // Fetch data:application/octet-stream;base64 URIs to unpack compressed URL fragments. 26 // Fetch data:application/octet-stream;base64 URIs to unpack compressed URL fragments.
27 "connect-src 'self' data:; " + 27 "connect-src 'self' data:; " +