From 91d385d8387b0421e478dd65ede9d918c53653a5 Mon Sep 17 00:00:00 2001 From: Mike Cao Date: Thu, 30 Nov 2023 14:54:45 -0800 Subject: [PATCH] Added frame-src to CSP. --- next.config.js | 1 + 1 file changed, 1 insertion(+) diff --git a/next.config.js b/next.config.js index a1e30c36..eaaf8fe7 100644 --- a/next.config.js +++ b/next.config.js @@ -9,6 +9,7 @@ const contentSecurityPolicy = [ `script-src 'self' 'unsafe-eval' 'unsafe-inline'`, `style-src 'self' 'unsafe-inline'`, `connect-src 'self' api.umami.is`, + `frame-src *`, ]; const cspHeader = (values = []) => ({