mirror of
				https://github.com/excalidraw/excalidraw.git
				synced 2025-11-04 04:44:31 +01:00 
			
		
		
		
	CSP: fix codesandbox (#1401)
* add csb to csp whitelist * add csb.app * allow child-src csp * add cdnjs.cloudflare * allow unsafe-eval
This commit is contained in:
		@@ -64,7 +64,7 @@
 | 
			
		||||
    <meta name="twitter:image" content="https://excalidraw.com/og-image.png" />
 | 
			
		||||
    <meta
 | 
			
		||||
      http-equiv="Content-Security-Policy"
 | 
			
		||||
      content="block-all-mixed-content; child-src 'none'; connect-src 'self' https: wss: http: ws:; default-src 'self'; font-src 'self' data: https: filesystem:; img-src 'self' data: https:; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https:;"
 | 
			
		||||
      content="block-all-mixed-content; child-src 'self' https://codesandbox.io https://*.csb.app; connect-src 'self' https: wss: http: ws:; default-src 'self'; font-src 'self' data: https: filesystem:; img-src 'self' data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://codesandbox.io https://*.csb.app https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https:;"
 | 
			
		||||
    />
 | 
			
		||||
    <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" />
 | 
			
		||||
    <link rel="stylesheet" href="fonts.css" />
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user