diff --git a/app/Http/Middleware/SecureHeaders.php b/app/Http/Middleware/SecureHeaders.php index fe2767717b..930f4af5e4 100644 --- a/app/Http/Middleware/SecureHeaders.php +++ b/app/Http/Middleware/SecureHeaders.php @@ -59,7 +59,7 @@ class SecureHeaders $csp = [ "default-src 'none'", "object-src 'self'", - sprintf("script-src 'nonce-%s' 'unsafe-inline' %s", $nonce, $google), + sprintf("script-src' 'nonce-%s' 'unsafe-inline' %s", $nonce, $google), "style-src 'self' 'unsafe-inline'", "base-uri 'self'", "font-src 'self' data:",