Skip to content

Commit 943985c

Browse files
authored
Fix font-src CSP (#1198)
1 parent e548c00 commit 943985c

File tree

5 files changed

+5
-5
lines changed

5 files changed

+5
-5
lines changed

mesop/server/static_file_serving.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -229,7 +229,7 @@ def add_security_headers(response: Response):
229229
csp = OrderedDict(
230230
{
231231
"default-src": "'self'",
232-
"font-src": "fonts.gstatic.com data:",
232+
"font-src": "'self' fonts.gstatic.com data:",
233233
# Mesop app developers should be able to iframe other sites.
234234
"frame-src": "*",
235235
# Mesop app developers should be able to load images and media from various origins.

mesop/tests/e2e/snapshots/web_security_test.ts_csp-allowed-iframe-parents.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
default-src 'self'
2-
font-src fonts.gstatic.com data:
2+
font-src 'self' fonts.gstatic.com data:
33
frame-src *
44
img-src 'self' data: https: http: blob:
55
media-src 'self' data: https: blob:

mesop/tests/e2e/snapshots/web_security_test.ts_csp-escaping.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
default-src 'self'
2-
font-src fonts.gstatic.com data:
2+
font-src 'self' fonts.gstatic.com data:
33
frame-src *
44
img-src 'self' data: https: http: blob:
55
media-src 'self' data: https: blob:

mesop/tests/e2e/snapshots/web_security_test.ts_csp-trusted-types.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
default-src 'self'
2-
font-src fonts.gstatic.com data:
2+
font-src 'self' fonts.gstatic.com data:
33
frame-src *
44
img-src 'self' data: https: http: blob:
55
media-src 'self' data: https: blob:

mesop/tests/e2e/snapshots/web_security_test.ts_csp.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
default-src 'self'
2-
font-src fonts.gstatic.com data:
2+
font-src 'self' fonts.gstatic.com data:
33
frame-src *
44
img-src 'self' data: https: http: blob:
55
media-src 'self' data: https: blob:

0 commit comments

Comments
 (0)