Merge pull request #3899 from overleaf/ae-csp-report-sample

Add 'report-sample' to script-src CSP directive

GitOrigin-RevId: 1a2c26339e7ef353a89fc264b0f186a1d313e1bc
This commit is contained in:
Alasdair Smith
2021-04-14 10:03:14 +01:00
committed by Copybot
parent c89beb7657
commit 676b70b2be

View File

@@ -24,7 +24,7 @@ module.exports = function({
res.locals.scriptNonce = scriptNonce
const directives = [
`script-src 'nonce-${scriptNonce}' 'unsafe-inline' 'strict-dynamic' https:`,
`script-src 'nonce-${scriptNonce}' 'unsafe-inline' 'strict-dynamic' https: 'report-sample'`,
`object-src 'none'`,
`base-uri 'none'`
]