csp: support old browsers without style-src-attr

This commit is contained in:
hiromi-mi 2020-06-20 09:50:32 +09:00
parent 58a14c4ab0
commit f0929c6bab

3
app.py
View file

@ -102,7 +102,8 @@ csp = {
"default-src": "'self'",
"style-src-attr": "'unsafe-inline'",
"script-src": "'self'", # to use nonce
"style-src": "'self'", # to use nonce
"style-src": "'unsafe-inline'", # for old browsers without support style-src-attr
"style-src-elem": "'self'",
}
talisman = Talisman(