allow inline styles. fixes #644

This commit is contained in:
Danny Coates 2017-11-15 10:54:13 -08:00
parent 490a1e88eb
commit b54f4575ee
No known key found for this signature in database
GPG Key ID: 4C442633C62E00CB
1 changed files with 20 additions and 22 deletions

View File

@ -42,7 +42,6 @@ module.exports = function(app) {
force: !IS_DEV force: !IS_DEV
}) })
); );
if (!IS_DEV) {
app.use( app.use(
helmet.contentSecurityPolicy({ helmet.contentSecurityPolicy({
directives: { directives: {
@ -54,7 +53,7 @@ module.exports = function(app) {
], ],
imgSrc: ["'self'", 'https://www.google-analytics.com'], imgSrc: ["'self'", 'https://www.google-analytics.com'],
scriptSrc: ["'self'"], scriptSrc: ["'self'"],
styleSrc: ["'self'", 'https://code.cdn.mozilla.net'], styleSrc: ["'self'", "'unsafe-inline'", 'https://code.cdn.mozilla.net'],
fontSrc: ["'self'", 'https://code.cdn.mozilla.net'], fontSrc: ["'self'", 'https://code.cdn.mozilla.net'],
formAction: ["'none'"], formAction: ["'none'"],
frameAncestors: ["'none'"], frameAncestors: ["'none'"],
@ -63,7 +62,6 @@ module.exports = function(app) {
} }
}) })
); );
}
app.use( app.use(
busboy({ busboy({
limits: { limits: {