Skip to content

Commit cecd853

Browse files
committed
fix: remove wasm-unsafe-eval from Content-Security-Policy header
1 parent 97b71ab commit cecd853

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

src/Ui/UiRequest.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -386,7 +386,7 @@ def sendHeader(self, status=200, content_type="text/html", noscript=False, allow
386386
other_port = config.ui_port
387387
frame_src = 'self'
388388

389-
headers["Content-Security-Policy"] = f"default-src 'none'; script-src 'nonce-{script_nonce}' 'wasm-unsafe-eval'; img-src 'self' blob: data:; style-src 'self' blob: 'unsafe-inline'; connect-src *; frame-src {frame_src}"
389+
headers["Content-Security-Policy"] = f"default-src 'none'; script-src 'nonce-{script_nonce}'; img-src 'self' blob: data:; style-src 'self' blob: 'unsafe-inline'; connect-src *; frame-src {frame_src}"
390390

391391
if allow_ajax:
392392
headers["Access-Control-Allow-Origin"] = "null"

0 commit comments

Comments
 (0)