about summary refs log tree commit diff
diff options
context:
space:
mode:
authorThibG <thib@sitedethib.com>2020-03-27 22:35:57 +0100
committerGitHub <noreply@github.com>2020-03-27 22:35:57 +0100
commit7ddbbdea6d4591e6cfe032a0dd212703776e5bb4 (patch)
tree8f21449e0d15f0da2b0afc99d148c1a652f1849c
parentbf1919e44abfc0cc0ea4afd2d3afe8fc274f4966 (diff)
Fix OCR not working on Safari because of unsupported worker-src CSP (#13323)
Fixes #13321
-rw-r--r--config/initializers/content_security_policy.rb2
1 files changed, 2 insertions, 0 deletions
diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb
index af7d16aaf..654e2e8cd 100644
--- a/config/initializers/content_security_policy.rb
+++ b/config/initializers/content_security_policy.rb
@@ -32,10 +32,12 @@ Rails.application.config.content_security_policy do |p|
 
     p.connect_src :self, :data, :blob, assets_host, media_host, Rails.configuration.x.streaming_api_base_url, *webpacker_urls
     p.script_src  :self, :unsafe_inline, :unsafe_eval, assets_host
+    p.child_src   :self, :blob, assets_host
     p.worker_src  :self, :blob, assets_host
   else
     p.connect_src :self, :data, :blob, assets_host, media_host, Rails.configuration.x.streaming_api_base_url
     p.script_src  :self, assets_host
+    p.child_src   :self, :blob, assets_host
     p.worker_src  :self, :blob, assets_host
   end
 end