csp: support old browsers without style-src-attr
This commit is contained in:
parent
58a14c4ab0
commit
f0929c6bab
1 changed files with 4 additions and 3 deletions
3
app.py
3
app.py
|
@ -102,7 +102,8 @@ csp = {
|
|||
"default-src": "'self'",
|
||||
"style-src-attr": "'unsafe-inline'",
|
||||
"script-src": "'self'", # to use nonce
|
||||
"style-src": "'self'", # to use nonce
|
||||
"style-src": "'unsafe-inline'", # for old browsers without support style-src-attr
|
||||
"style-src-elem": "'self'",
|
||||
}
|
||||
|
||||
talisman = Talisman(
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue