aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRafael França <rafaelmfranca@gmail.com>2018-01-30 18:30:13 -0500
committerGitHub <noreply@github.com>2018-01-30 18:30:13 -0500
commitbec74e1d4a05eb18eaf0dea9506b43569fd5cd05 (patch)
tree5141631c2e13f6ebed76ba66802f4efdefd6560f
parent54bb2f74b5156b4251582842b0edc8e216958e01 (diff)
parent39c4a5c40b3abde1d3dee76a3ccdd326f77f60b0 (diff)
downloadrails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.tar.gz
rails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.tar.bz2
rails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.zip
Merge pull request #31830 from rafaelfranca/disable-csp-by-default
Disable CSP by default
-rw-r--r--railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt20
1 files changed, 10 insertions, 10 deletions
diff --git a/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt b/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt
index c82324ae4d..edde7f42b8 100644
--- a/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt
+++ b/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt
@@ -4,17 +4,17 @@
# For further information see the following documentation
# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
-Rails.application.config.content_security_policy do |policy|
- policy.default_src :self, :https
- policy.font_src :self, :https, :data
- policy.img_src :self, :https, :data
- policy.object_src :none
- policy.script_src :self, :https, :unsafe_inline
- policy.style_src :self, :https, :unsafe_inline
+# Rails.application.config.content_security_policy do |policy|
+# policy.default_src :self, :https
+# policy.font_src :self, :https, :data
+# policy.img_src :self, :https, :data
+# policy.object_src :none
+# policy.script_src :self, :https
+# policy.style_src :self, :https, :unsafe_inline
- # Specify URI for violation reports
- # policy.report_uri "/csp-violation-report-endpoint"
-end
+# # Specify URI for violation reports
+# # policy.report_uri "/csp-violation-report-endpoint"
+# end
# Report CSP violations to a specified URI
# For further information see the following documentation: