From 5cd4aeb1aa08aaab2cb00a9de841783310790caa Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Thu, 17 May 2018 19:10:23 +0100 Subject: [PATCH 1/1] Preserve schemes in security policy --- config/initializers/secure_headers.rb | 1 + 1 file changed, 1 insertion(+) diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index bb901e375..ba9aa496f 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -1,5 +1,6 @@ if defined?(CSP_REPORT_URL) csp_policy = { + :preserve_schemes => true, :default_src => %w['self'], :child_src => %w['self'], :connect_src => %w['self'], -- 2.43.2