From 92c5e97f85f5aeb0e3300b5e9d0aca24595883b5 Mon Sep 17 00:00:00 2001 From: Bruno Quaresma Date: Thu, 8 Dec 2022 16:53:50 -0300 Subject: [PATCH] fix: Fix CSP style directive for Monaco editor (#5360) --- site/site.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/site/site.go b/site/site.go index 924b88f195..d264071fff 100644 --- a/site/site.go +++ b/site/site.go @@ -269,9 +269,9 @@ func cspHeaders(next http.Handler) http.Handler { // https://cdn.jsdelivr.net is used by monaco editor on FE for Syntax Highlight // https://github.com/suren-atoyan/monaco-react/issues/168 CSPDirectiveScriptSrc: {"'self' https://cdn.jsdelivr.net"}, + CSPDirectiveStyleSrc: {"'self' 'unsafe-inline' https://cdn.jsdelivr.net"}, // data: is used by monaco editor on FE for Syntax Highlight - CSPDirectiveFontSrc: {"'self' data:"}, - CSPDirectiveStyleSrc: {"'self' 'unsafe-inline'"}, + CSPDirectiveFontSrc: {"'self' data:"}, // object-src is needed to support code-server CSPDirectiveObjectSrc: {"'self'"}, // blob: for loading the pwa manifest for code-server