fix: CSP — ajout cloudflareinsights.com + legacy.js deja corrige
CI / lint (push) Failing after 3s
CI / test (push) Has been skipped
CI / build (push) Has been skipped
CI / e2e (push) Has been skipped
CI / security (push) Failing after -3s

- CSP script-src: ajout https://static.cloudflareinsights.com
- legacy.js ligne 98 a deja le null-check if(filterBtn)
- L'erreur production vient d'un ancien deploy, sera resolu au prochain rebuild
This commit is contained in:
2026-06-15 23:29:46 -04:00
parent d1841a057d
commit 23f4f9f4f2
+1 -1
View File
@@ -545,7 +545,7 @@ class SecurityHeadersMiddleware(BaseHTTPMiddleware):
response.headers["Referrer-Policy"] = "strict-origin-when-cross-origin"
response.headers["Content-Security-Policy"] = (
"default-src 'self'; "
"script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://unpkg.com https://esm.sh https://cdn.jsdelivr.net; "
"script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://unpkg.com https://esm.sh https://cdn.jsdelivr.net https://static.cloudflareinsights.com; "
"style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com https://cdn.jsdelivr.net; "
"img-src 'self' data: blob:; "
"connect-src 'self' https://esm.sh https://unpkg.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.jsdelivr.net; "