fix: add turnstile in scriptsrc

This commit is contained in:
murdle 2026-03-01 01:16:01 +02:00
parent 960fc652b1
commit b22d5f9f9a

View File

@ -289,7 +289,7 @@ function createAppServerInitializer(context: ServiceInitializationContext): Serv
},
cspDirectives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'", "'unsafe-inline'"],
scriptSrc: ["'self'", "'unsafe-inline'", "https://challenges.cloudflare.com"],
styleSrc: ["'self'", "'unsafe-inline'", staticCdnHost],
imgSrc: ["'self'", 'data:', 'blob:', publicUrlHost, mediaUrlHost, staticCdnHost],
connectSrc: ["'self'", 'wss:', 'ws:', publicUrlHost],