Fix CSP: allow unsafe-inline scripts for SvelteKit hydration
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -34,7 +34,7 @@ export const handle: Handle = async ({ event, resolve }) => {
|
||||
|
||||
response.headers.set(
|
||||
'Content-Security-Policy',
|
||||
"default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none'"
|
||||
"default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none'"
|
||||
);
|
||||
response.headers.set('X-Content-Type-Options', 'nosniff');
|
||||
|
||||
|
||||
Reference in New Issue
Block a user