Add missing unsafe-inline CSP directive

Dropbox loads an external script that adds inline javascript. Therefore, this addition is needed when enabling dropbox support.

Signed-off-by: Erik Michelson <github@erik.michelson.eu>
This commit is contained in:
Erik Michelson 2020-08-23 01:29:53 +02:00
parent f821da6c09
commit 8932260360
No known key found for this signature in database
GPG key ID: DB99ADDDC5C0AF82

View file

@ -33,7 +33,7 @@ var googleAnalyticsDirectives = {
}
var dropboxDirectives = {
scriptSrc: ['https://www.dropbox.com']
scriptSrc: ['https://www.dropbox.com', '\'unsafe-inline\'']
}
CspStrategy.computeDirectives = function () {