From bd7094b9f52b7165518fb20b4a0065c06d44ea0c Mon Sep 17 00:00:00 2001 From: Joel Date: Thu, 15 May 2025 14:13:49 +0800 Subject: [PATCH] chore: image allow "data:" in csp (#19728) --- web/middleware.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/middleware.ts b/web/middleware.ts index 01c78f1956..ac016945fd 100644 --- a/web/middleware.ts +++ b/web/middleware.ts @@ -37,7 +37,7 @@ export function middleware(request: NextRequest) { style-src 'self' 'unsafe-inline' ${scheme_source} ${whiteList}; worker-src 'self' ${scheme_source} ${csp} ${whiteList}; media-src 'self' ${scheme_source} ${csp} ${whiteList}; - img-src *; + img-src * data:; font-src 'self'; object-src 'none'; base-uri 'self';