mirror of https://github.com/langgenius/dify.git
refactor: update Content Security Policy to allow 'wasm-unsafe-eval' and set nonce in response headers
This commit is contained in:
parent
ed6fd6f3d9
commit
138a8b9f7a
|
|
@ -33,7 +33,7 @@ export function middleware(request: NextRequest) {
|
|||
const cspHeader = `
|
||||
default-src 'self' ${scheme_source} ${csp} ${whiteList};
|
||||
connect-src 'self' ${scheme_source} ${csp} ${whiteList};
|
||||
script-src 'self' ${scheme_source} ${csp} ${whiteList};
|
||||
script-src 'self' 'wasm-unsafe-eval' ${scheme_source} ${csp} ${whiteList};
|
||||
style-src 'self' 'unsafe-inline' ${scheme_source} ${whiteList};
|
||||
worker-src 'self' ${scheme_source} ${csp} ${whiteList};
|
||||
media-src 'self' ${scheme_source} ${csp} ${whiteList};
|
||||
|
|
@ -56,6 +56,7 @@ export function middleware(request: NextRequest) {
|
|||
contentSecurityPolicyHeaderValue,
|
||||
)
|
||||
|
||||
response.headers.set('x-nonce', nonce)
|
||||
response.headers.set(
|
||||
'Content-Security-Policy',
|
||||
contentSecurityPolicyHeaderValue,
|
||||
|
|
|
|||
Loading…
Reference in New Issue