From: Tom Hughes Date: Thu, 17 May 2018 18:10:23 +0000 (+0100) Subject: Preserve schemes in security policy X-Git-Tag: live~3036 X-Git-Url: https://git.openstreetmap.org/rails.git/commitdiff_plain/5cd4aeb1aa08aaab2cb00a9de841783310790caa?hp=a6feffca9b1b966e49956b590420e16e4ebb25e9 Preserve schemes in security policy --- diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index bb901e375..ba9aa496f 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -1,5 +1,6 @@ if defined?(CSP_REPORT_URL) csp_policy = { + :preserve_schemes => true, :default_src => %w['self'], :child_src => %w['self'], :connect_src => %w['self'],