Skip to content

Commit

Permalink
CSP : autorise images venant du Géoportail IGN (#4304)
Browse files Browse the repository at this point in the history
  • Loading branch information
AntoineAugusti authored Nov 12, 2024
1 parent f9996ab commit a5a7897
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ defmodule TransportWeb.Plugs.CustomSecureBrowserHeaders do
connect-src *;
font-src *;
frame-ancestors 'none';
img-src 'self' data: https://api.mapbox.com https://static.data.gouv.fr https://www.data.gouv.fr https://*.dmcdn.net #{logos_bucket_url};
img-src 'self' data: https://api.mapbox.com https://data.geopf.fr https://static.data.gouv.fr https://www.data.gouv.fr https://*.dmcdn.net #{logos_bucket_url};
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://stats.data.gouv.fr/matomo.js;
frame-src https://*.dailymotion.com;
style-src 'self' 'nonce-#{nonce}' #{vega_hash_values};
Expand All @@ -60,7 +60,7 @@ defmodule TransportWeb.Plugs.CustomSecureBrowserHeaders do
connect-src *;
font-src *;
frame-ancestors 'none';
img-src 'self' data: https://api.mapbox.com https://static.data.gouv.fr https://demo-static.data.gouv.fr https://www.data.gouv.fr https://demo.data.gouv.fr https://*.dmcdn.net #{logos_bucket_url};
img-src 'self' data: https://api.mapbox.com https://data.geopf.fr https://static.data.gouv.fr https://demo-static.data.gouv.fr https://www.data.gouv.fr https://demo.data.gouv.fr https://*.dmcdn.net #{logos_bucket_url};
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://stats.data.gouv.fr/matomo.js;
frame-src https://*.dailymotion.com;
style-src 'self' 'nonce-#{nonce}' #{vega_hash_values};
Expand Down

0 comments on commit a5a7897

Please sign in to comment.