Be backwards compatible.

This commit is contained in:
James Cole
2020-01-09 17:03:59 +01:00
parent 7f0ac79c5c
commit 8c6f8460a2

View File

@@ -59,7 +59,7 @@ class SecureHeaders
$csp = [
"default-src 'none'",
"object-src 'self'",
sprintf("script-src 'nonce-%s' %s", $nonce, $google),
sprintf("script-src 'nonce-%s' unsafe-inline %s", $nonce, $google),
"style-src 'self' 'unsafe-inline'",
"base-uri 'self'",
"font-src 'self' data:",