From 591b11eafcc49a7812390a03d29596b4a96ad5f8 Mon Sep 17 00:00:00 2001 From: shibayashi Date: Mon, 26 Nov 2018 20:48:24 +0100 Subject: [PATCH] Add manifest-src to allow manifest.json --- lib/pleroma/plugs/http_security_plug.ex | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/pleroma/plugs/http_security_plug.ex b/lib/pleroma/plugs/http_security_plug.ex index 31c7332f8..84d6506e3 100644 --- a/lib/pleroma/plugs/http_security_plug.ex +++ b/lib/pleroma/plugs/http_security_plug.ex @@ -39,6 +39,7 @@ defp csp_string do "font-src 'self'", "script-src 'self'", "connect-src 'self' " <> String.replace(Pleroma.Web.Endpoint.static_url(), "http", "ws"), + "manifest-src 'self'", "upgrade-insecure-requests" ] |> Enum.join("; ")