Allow blob: protocol (#2166)

* Allow blob: protocol

* Fix quotes
This commit is contained in:
Ivanq 2019-08-20 10:42:01 +00:00 committed by ZeroNet
parent 0e236e53fd
commit 24b3651d2e

View file

@ -259,7 +259,7 @@ class UiRequest(object):
if noscript:
headers["Content-Security-Policy"] = "default-src 'none'; sandbox allow-top-navigation allow-forms; img-src 'self'; font-src 'self'; media-src 'self'; style-src 'self' 'unsafe-inline';"
elif script_nonce and self.isScriptNonceSupported():
headers["Content-Security-Policy"] = "default-src 'none'; script-src 'nonce-{0}'; img-src 'self'; style-src 'self' 'unsafe-inline'; connect-src *; frame-src 'self'".format(script_nonce)
headers["Content-Security-Policy"] = "default-src 'none'; script-src 'nonce-{0}'; img-src 'self' blob:; style-src 'self' blob: 'unsafe-inline'; connect-src *; frame-src 'self' blob:".format(script_nonce)
if allow_ajax:
headers["Access-Control-Allow-Origin"] = "null"