Skip to content

Commit c51b0a0

Browse files
committed
feat(security): update img-src directive to allow localhost HTTP in development environment
1 parent dda4ec3 commit c51b0a0

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

apps/web/src/utils/security-headers.ts

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,10 @@ function getSecurityHeaders(
5454
? `'self' 'nonce-${nonce}' https://static.cloudflareinsights.com https://cdn.jsdelivr.net blob:`
5555
: "'self' https://static.cloudflareinsights.com https://cdn.jsdelivr.net blob:", // React/Vite compatibility + Cloudflare Insights + Monaco Editor
5656
"style-src": "'self' 'unsafe-inline' https://cdn.jsdelivr.net", // Tailwind/CSS-in-JS support + Monaco Editor
57-
"img-src": "'self' data: https:",
57+
"img-src":
58+
environment === "development"
59+
? "'self' data: https: http://localhost:*" // Allow localhost HTTP in dev
60+
: "'self' data: https:",
5861
"font-src": "'self' data: https://cdn.jsdelivr.net",
5962
"connect-src":
6063
environment === "development"

0 commit comments

Comments
 (0)