From f01ae28b8cb670122fe2d3d629e617e8906ac5fb Mon Sep 17 00:00:00 2001 From: Michael Scherer Date: Thu, 17 Oct 2019 12:38:00 -0400 Subject: [PATCH] Fix the CSP policy to let the Fedora magazine widget work Since https://pagure.io/fedora-web/websites/pull-request/57 got merged, we also need to fix the CSP policy since it get the article from a local json file on the server (see the PR for details) --- roles/fedora-web/getfedora/files/csp.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/fedora-web/getfedora/files/csp.conf b/roles/fedora-web/getfedora/files/csp.conf index 5917bbbdad..7c6b5c6d90 100644 --- a/roles/fedora-web/getfedora/files/csp.conf +++ b/roles/fedora-web/getfedora/files/csp.conf @@ -1 +1 @@ -Header always set Content-Security-Policy "default-src 'none'; img-src 'self' https://fedoramagazine.org; script-src 'self'; style-src 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; connect-src https://fedoramagazine.org https://builds.coreos.fedoraproject.org; " +Header always set Content-Security-Policy "default-src 'none'; img-src 'self' https://fedoramagazine.org; script-src 'self'; style-src 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://builds.coreos.fedoraproject.org; "