Enforce CSP in dev environment

pull/417/head
Thibaut Courouble 9 years ago
parent d9e64f9d06
commit bdda2fbfe6

@ -66,6 +66,8 @@ class App < Sinatra::Application
use BetterErrors::Middleware use BetterErrors::Middleware
BetterErrors.application_root = File.expand_path('..', __FILE__) BetterErrors.application_root = File.expand_path('..', __FILE__)
BetterErrors.editor = :sublime BetterErrors.editor = :sublime
set :csp, "default-src 'self' *; script-src 'self' 'unsafe-inline' *; font-src data:; style-src 'self' 'unsafe-inline' *; img-src 'self' * data:;"
end end
configure :production do configure :production do

Loading…
Cancel
Save