Feature(360): attempt to fix CSP

This commit is contained in:
Pieter Vander Vennet 2025-03-30 19:38:36 +02:00
parent a30f25f42a
commit 558b19f8d7
5 changed files with 132 additions and 55 deletions

View file

@ -426,7 +426,7 @@ class GenerateLayouts extends Script {
const csp: Record<string, string> = {
"default-src": "'self'",
"child-src": "'self' blob: ",
"img-src": "* data:", // maplibre depends on 'data:' to load
"img-src": "* data: blob:", // maplibre depends on 'data:' to load
"report-to": "https://report.mapcomplete.org/csp",
"worker-src": "'self' blob:", // Vite somehow loads the worker via a 'blob'
"style-src": "'self' 'unsafe-inline'", // unsafe-inline is needed to change the default background pin colours