diff --git a/src/dashboard/mod.rs b/src/dashboard/mod.rs index 4c0ed61a..460e5f71 100644 --- a/src/dashboard/mod.rs +++ b/src/dashboard/mod.rs @@ -83,7 +83,7 @@ pub fn router(state: AppState) -> Router { // Security headers let csp_header: SetResponseHeaderLayer = SetResponseHeaderLayer::overriding( header::CONTENT_SECURITY_POLICY, - "default-src 'self'; script-src 'self' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com; font-src 'self' https://cdnjs.cloudflare.com https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self' ws:;" + "default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com; font-src 'self' https://cdnjs.cloudflare.com https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self' ws:;" .parse() .unwrap(), );