From e53f9bc172db87ee1909736db8d15297a776a6cc Mon Sep 17 00:00:00 2001 From: eternal-flame-AD Date: Mon, 11 Nov 2024 21:54:57 -0600 Subject: [PATCH] allow self-embed (previews, etc.) Signed-off-by: eternal-flame-AD --- packages/backend/src/server/csp.ts | 1 - 1 file changed, 1 deletion(-) diff --git a/packages/backend/src/server/csp.ts b/packages/backend/src/server/csp.ts index 1797d93707..45b37fbd06 100644 --- a/packages/backend/src/server/csp.ts +++ b/packages/backend/src/server/csp.ts @@ -44,7 +44,6 @@ export function generateCSP(hashedMap: Map, options: { ['style-src-attr', ['\'self\'', '\'unsafe-inline\'']], ['script-src', ['\'self\'', '\'wasm-unsafe-eval\'', ...scripts]], ['object-src', ['\'none\'']], - ['frame-src', ['\'none\'']], ['base-uri', ['\'self\'']], ['form-action', ['\'self\'']], ['child-src', ['\'self\'']],