diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb index d6e880ba0..6c47437c4 100644 --- a/config/initializers/content_security_policy.rb +++ b/config/initializers/content_security_policy.rb @@ -7,7 +7,7 @@ policy.font_src :self, :https, :data policy.img_src :self, :https, :data policy.object_src :none - policy.script_src :self, :https, :unsafe_eval, *allowed_script_sources + policy.script_src :self, :https, :unsafe_inline, :unsafe_eval, *allowed_script_sources policy.style_src :self, :https, :unsafe_inline policy.report_uri '/csp-violation-report' end