We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent b0bee37 commit 94d8815Copy full SHA for 94d8815
AspNetCoreRazor/SecurityHeadersDefinitions.cs
@@ -22,7 +22,7 @@ public static HeaderPolicyCollection GetHeaderPolicyCollection(bool isDev)
22
builder.AddFontSrc().Self();
23
builder.AddStyleSrc().Self(); // .UnsafeInline();
24
builder.AddBaseUri().Self();
25
- builder.AddScriptSrc().Self().UnsafeInline().WithNonce();
+ builder.AddScriptSrc().UnsafeInline().WithNonce();
26
builder.AddFrameAncestors().None();
27
//builder.AddCustomDirective("require-trusted-types-for", "'script'");
28
})
@@ -55,4 +55,4 @@ public static HeaderPolicyCollection GetHeaderPolicyCollection(bool isDev)
55
56
return policy;
57
}
58
-}
+}
0 commit comments