mirror of
https://github.com/alam00000/bentopdf.git
synced 2026-04-22 06:57:40 -04:00
fix(security): update script-src directive to include 'blob:'
This commit is contained in:
3
.gitignore
vendored
3
.gitignore
vendored
@@ -49,4 +49,5 @@ libreoffice-wasm-package
|
||||
bentopdf-*.tgz
|
||||
|
||||
# test
|
||||
dist-test
|
||||
dist-test
|
||||
test
|
||||
@@ -55,7 +55,7 @@ const fontOrigins = uniq([ocrFontOrigin].filter(Boolean));
|
||||
|
||||
const directives = [
|
||||
`default-src 'self'`,
|
||||
`script-src 'self' 'wasm-unsafe-eval' 'unsafe-eval' ${scriptOrigins.join(' ')}`.trim(),
|
||||
`script-src 'self' 'wasm-unsafe-eval' 'unsafe-eval' blob: ${scriptOrigins.join(' ')}`.trim(),
|
||||
`worker-src 'self' blob:`,
|
||||
`style-src 'self' 'unsafe-inline' https://fonts.googleapis.com`,
|
||||
`img-src 'self' data: blob: https:`,
|
||||
|
||||
Reference in New Issue
Block a user