diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb index 68d3751fce..aebac78eca 100644 --- a/config/initializers/content_security_policy.rb +++ b/config/initializers/content_security_policy.rb @@ -33,9 +33,9 @@ if Rails.env.production? p.frame_ancestors :none p.script_src :self, assets_host p.font_src :self, assets_host - p.img_src :self, :data, :blob, *data_hosts + p.img_src :self, :data, :blob, "blob.jortage.com", *data_hosts p.style_src :self, assets_host - p.media_src :self, :data, *data_hosts + p.media_src :self, :data, "blob.jortage.com", *data_hosts p.frame_src :self, :https p.child_src :self, :blob, assets_host p.worker_src :self, :blob, assets_host