about summary refs log tree commit diff
diff options
context:
space:
mode:
authorClaire <claire.github-309c@sitedethib.com>2022-11-16 16:28:48 +0100
committerGitHub <noreply@github.com>2022-11-16 16:28:48 +0100
commit8c56441b4a52f23d4793f35fdf27a815cced0d61 (patch)
tree9f45f94f5d8dce681a8b1e540604ca48cfbba5ea
parentad84fd25f131b4ec3e8b775f3596409fc34f71f2 (diff)
Add form-action CSP directive (#1948)
-rw-r--r--config/initializers/content_security_policy.rb1
1 files changed, 1 insertions, 0 deletions
diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb
index 0174e0636..ce8aa7af2 100644
--- a/config/initializers/content_security_policy.rb
+++ b/config/initializers/content_security_policy.rb
@@ -41,6 +41,7 @@ if Rails.env.production?
     p.worker_src      :self, :blob, assets_host
     p.connect_src     :self, :blob, :data, Rails.configuration.x.streaming_api_base_url, *data_hosts
     p.manifest_src    :self, assets_host
+    p.form_action     :self
   end
 end