@@ -131,20 +131,7 @@ export const buildTimeCSPDirectives: CSPDirectives = {
131131 'script-src' : [ ...STATIC_SCRIPT_SRC ] ,
132132 'style-src' : [ "'self'" , "'unsafe-inline'" , 'https://fonts.googleapis.com' ] ,
133133
134- 'img-src' : [
135- ...STATIC_IMG_SRC ,
136- ...( env . S3_BUCKET_NAME && env . AWS_REGION
137- ? [ `https://${ env . S3_BUCKET_NAME } .s3.${ env . AWS_REGION } .amazonaws.com` ]
138- : [ ] ) ,
139- ...( env . S3_KB_BUCKET_NAME && env . AWS_REGION
140- ? [ `https://${ env . S3_KB_BUCKET_NAME } .s3.${ env . AWS_REGION } .amazonaws.com` ]
141- : [ ] ) ,
142- ...( env . S3_CHAT_BUCKET_NAME && env . AWS_REGION
143- ? [ `https://${ env . S3_CHAT_BUCKET_NAME } .s3.${ env . AWS_REGION } .amazonaws.com` ]
144- : [ ] ) ,
145- ...getHostnameFromUrl ( env . NEXT_PUBLIC_BRAND_LOGO_URL ) ,
146- ...getHostnameFromUrl ( env . NEXT_PUBLIC_BRAND_FAVICON_URL ) ,
147- ] ,
134+ 'img-src' : [ ...STATIC_IMG_SRC ] ,
148135
149136 'media-src' : [ "'self'" , 'blob:' ] ,
150137 'worker-src' : [ "'self'" , 'blob:' ] ,
@@ -200,14 +187,13 @@ export function generateRuntimeCSP(): string {
200187 const ollamaUrl = getEnv ( 'OLLAMA_URL' ) || ( isDev ? DEFAULT_OLLAMA_URL : '' )
201188
202189 const brandLogoDomains = getHostnameFromUrl ( getEnv ( 'NEXT_PUBLIC_BRAND_LOGO_URL' ) )
203- const brandFaviconDomains = getHostnameFromUrl ( getEnv ( 'NEXT_PUBLIC_BRAND_FAVICON_URL' ) )
204190 const privacyDomains = getHostnameFromUrl ( getEnv ( 'NEXT_PUBLIC_PRIVACY_URL' ) )
205191 const termsDomains = getHostnameFromUrl ( getEnv ( 'NEXT_PUBLIC_TERMS_URL' ) )
206192
207193 const runtimeDirectives : CSPDirectives = {
208194 ...buildTimeCSPDirectives ,
209195
210- 'img-src' : [ ...STATIC_IMG_SRC , ... brandLogoDomains , ... brandFaviconDomains ] ,
196+ 'img-src' : [ ...STATIC_IMG_SRC ] ,
211197
212198 'connect-src' : [
213199 ...STATIC_CONNECT_SRC ,
0 commit comments