From c801da45f335019e1bf54f0f76e0041ae8f390f4 Mon Sep 17 00:00:00 2001 From: Kyle Carberry Date: Fri, 8 Jul 2022 21:35:59 -0500 Subject: [PATCH] fix: Add https: to image CSP to allow external images (#2870) This broke external application icons. --- site/site.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/site/site.go b/site/site.go index a8d1147381..8e9528fa6a 100644 --- a/site/site.go +++ b/site/site.go @@ -280,7 +280,7 @@ func cspHeaders(next http.Handler) http.Handler { // https: allows loading images from external sources. This is not ideal // but is required for the templates page that renders readmes. // We should find a better solution in the future. - CSPDirectiveImgSrc: {"'self' data:"}, + CSPDirectiveImgSrc: {"'self' https: data:"}, CSPDirectiveFormAction: {"'self'"}, CSPDirectiveMediaSrc: {"'self'"}, // Report all violations back to the server to log