We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent dda4ec3 commit c51b0a0Copy full SHA for c51b0a0
1 file changed
apps/web/src/utils/security-headers.ts
@@ -54,7 +54,10 @@ function getSecurityHeaders(
54
? `'self' 'nonce-${nonce}' https://static.cloudflareinsights.com https://cdn.jsdelivr.net blob:`
55
: "'self' https://static.cloudflareinsights.com https://cdn.jsdelivr.net blob:", // React/Vite compatibility + Cloudflare Insights + Monaco Editor
56
"style-src": "'self' 'unsafe-inline' https://cdn.jsdelivr.net", // Tailwind/CSS-in-JS support + Monaco Editor
57
- "img-src": "'self' data: https:",
+ "img-src":
58
+ environment === "development"
59
+ ? "'self' data: https: http://localhost:*" // Allow localhost HTTP in dev
60
+ : "'self' data: https:",
61
"font-src": "'self' data: https://cdn.jsdelivr.net",
62
"connect-src":
63
environment === "development"
0 commit comments