diff options
author | yuuji.yaginuma <yuuji.yaginuma@gmail.com> | 2019-07-18 09:31:51 +0900 |
---|---|---|
committer | yuuji.yaginuma <yuuji.yaginuma@gmail.com> | 2019-07-18 10:00:54 +0900 |
commit | efae4c268bbecbfbf8020c3302183ce0887f083a (patch) | |
tree | 6d9ab6828d90188287fc815c84bdafd3deef4176 /actionpack/lib/action_dispatch/http | |
parent | c5a24c8ebba543687c11f893584618a20316fe34 (diff) | |
download | rails-efae4c268bbecbfbf8020c3302183ce0887f083a.tar.gz rails-efae4c268bbecbfbf8020c3302183ce0887f083a.tar.bz2 rails-efae4c268bbecbfbf8020c3302183ce0887f083a.zip |
Add support for script-src-attr / elem and style-src-attr / elem directives
These directives can be used in Chrome 75.
Ref: https://www.chromestatus.com/feature/5141352765456384
Diffstat (limited to 'actionpack/lib/action_dispatch/http')
-rw-r--r-- | actionpack/lib/action_dispatch/http/content_security_policy.rb | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/actionpack/lib/action_dispatch/http/content_security_policy.rb b/actionpack/lib/action_dispatch/http/content_security_policy.rb index 7dedecef34..9c430b57e3 100644 --- a/actionpack/lib/action_dispatch/http/content_security_policy.rb +++ b/actionpack/lib/action_dispatch/http/content_security_policy.rb @@ -137,7 +137,11 @@ module ActionDispatch #:nodoc: object_src: "object-src", prefetch_src: "prefetch-src", script_src: "script-src", + script_src_attr: "script-src-attr", + script_src_elem: "script-src-elem", style_src: "style-src", + style_src_attr: "style-src-attr", + style_src_elem: "style-src-elem", worker_src: "worker-src" }.freeze |