From 50700d39e3b8a23b7fcd14bd3a23cfca7b49a5fc Mon Sep 17 00:00:00 2001 From: Tommy Date: Fri, 31 Jan 2025 02:03:31 -0700 Subject: [PATCH] Add blob: to connect-src Signed-off-by: Tommy --- etc/nginx/conf.d/element.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/etc/nginx/conf.d/element.conf b/etc/nginx/conf.d/element.conf index 112411d..0231684 100644 --- a/etc/nginx/conf.d/element.conf +++ b/etc/nginx/conf.d/element.conf @@ -9,7 +9,7 @@ server { include /etc/nginx/headers.conf; proxy_hide_header Content-Security-Policy; - add_header Content-Security-Policy "default-src 'none'; connect-src 'self' https://arcticfoxes.net https://matrix.arcticfoxes.net https://syncv3.arcticfoxes.net; font-src 'self'; img-src 'self' https://arcticfoxes.net https://matrix.arcticfoxes.net blob: data:; manifest-src 'self'; media-src 'self' https://matrix.arcticfoxes.net blob: data:; script-src 'self' 'unsafe-eval' https://www.recaptcha.net https://www.gstatic.com; style-src 'self' 'unsafe-inline'; frame-src 'self' https://www.recaptcha.net blob:; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'none'"; + add_header Content-Security-Policy "default-src 'none'; connect-src 'self' https://arcticfoxes.net https://matrix.arcticfoxes.net https://syncv3.arcticfoxes.net blob:; font-src 'self'; img-src 'self' https://arcticfoxes.net https://matrix.arcticfoxes.net blob: data:; manifest-src 'self'; media-src 'self' https://matrix.arcticfoxes.net blob: data:; script-src 'self' 'unsafe-eval' https://www.recaptcha.net https://www.gstatic.com; style-src 'self' 'unsafe-inline'; frame-src 'self' https://www.recaptcha.net blob:; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'none'"; location / { proxy_pass http://127.0.0.1:81;