diff options
author | Rafael França <rafaelmfranca@gmail.com> | 2018-01-30 18:30:13 -0500 |
---|---|---|
committer | GitHub <noreply@github.com> | 2018-01-30 18:30:13 -0500 |
commit | bec74e1d4a05eb18eaf0dea9506b43569fd5cd05 (patch) | |
tree | 5141631c2e13f6ebed76ba66802f4efdefd6560f /railties/lib | |
parent | 54bb2f74b5156b4251582842b0edc8e216958e01 (diff) | |
parent | 39c4a5c40b3abde1d3dee76a3ccdd326f77f60b0 (diff) | |
download | rails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.tar.gz rails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.tar.bz2 rails-bec74e1d4a05eb18eaf0dea9506b43569fd5cd05.zip |
Merge pull request #31830 from rafaelfranca/disable-csp-by-default
Disable CSP by default
Diffstat (limited to 'railties/lib')
-rw-r--r-- | railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt | 20 |
1 files changed, 10 insertions, 10 deletions
diff --git a/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt b/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt index c82324ae4d..edde7f42b8 100644 --- a/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt +++ b/railties/lib/rails/generators/rails/app/templates/config/initializers/content_security_policy.rb.tt @@ -4,17 +4,17 @@ # For further information see the following documentation # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy -Rails.application.config.content_security_policy do |policy| - policy.default_src :self, :https - policy.font_src :self, :https, :data - policy.img_src :self, :https, :data - policy.object_src :none - policy.script_src :self, :https, :unsafe_inline - policy.style_src :self, :https, :unsafe_inline +# Rails.application.config.content_security_policy do |policy| +# policy.default_src :self, :https +# policy.font_src :self, :https, :data +# policy.img_src :self, :https, :data +# policy.object_src :none +# policy.script_src :self, :https +# policy.style_src :self, :https, :unsafe_inline - # Specify URI for violation reports - # policy.report_uri "/csp-violation-report-endpoint" -end +# # Specify URI for violation reports +# # policy.report_uri "/csp-violation-report-endpoint" +# end # Report CSP violations to a specified URI # For further information see the following documentation: |