Skip to content

Commit 83a273d

Browse files
Allow ic0.app in CSP (#525)
1 parent 2c14237 commit 83a273d

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

backend-tests/backend-tests.hs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -437,7 +437,7 @@ validateSecurityHeaders resp = do
437437
\window-placement=(),\
438438
\xr-spatial-tracking=()"
439439
validateHeaderMatches resp "Content-Security-Policy" "^default-src 'none';\
440-
\connect-src 'self';\
440+
\connect-src 'self' https://ic0.app;\
441441
\img-src 'self' data:;\
442442
\script-src 'sha256-[a-zA-Z0-9\\/=+]+' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https:;\
443443
\base-uri 'none';\

src/internet_identity/src/main.rs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -835,7 +835,7 @@ fn security_headers() -> Vec<HeaderField> {
835835
(
836836
"Content-Security-Policy".to_string(),
837837
"default-src 'none';\
838-
connect-src 'self';\
838+
connect-src 'self' https://ic0.app;\
839839
img-src 'self' data:;\
840840
script-src 'sha256-syYd+YuWeLD80uCtKwbaGoGom63a0pZE5KqgtA7W1d8=' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https:;\
841841
base-uri 'none';\

0 commit comments

Comments
 (0)