diff --git a/scouting.gateway-gamers.net.conf b/scouting.gateway-gamers.net.conf index 9f11a94..924daf5 100644 --- a/scouting.gateway-gamers.net.conf +++ b/scouting.gateway-gamers.net.conf @@ -28,7 +28,12 @@ server { add_header X-Frame-Options "SAMEORIGIN" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always; - add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always; + # style-src needs 'unsafe-inline': the app sets bar-chart widths via + # inline style="width:X%" through innerHTML, which CSP's style-src + # blocks without it (script-src stays locked down — this only affects + # CSS, and nothing here renders untrusted external content into a + # style attribute). + add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always; location / { try_files $uri $uri/ =404;