fix: allow inline styles in CSP so bar-chart widths actually apply
style-src 'self' (without unsafe-inline) silently blocks style="..." attributes introduced via innerHTML — the CSS parses fine and the attribute is present in the DOM, but the browser never applies it, so every bar rendered at its track's full width regardless of its real percentage. script-src stays locked down; this only loosens CSS, and no untrusted external content is ever rendered into a style attribute here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -28,7 +28,12 @@ server {
|
|||||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||||||
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
|
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
|
||||||
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always;
|
# style-src needs 'unsafe-inline': the app sets bar-chart widths via
|
||||||
|
# inline style="width:X%" through innerHTML, which CSP's style-src
|
||||||
|
# blocks without it (script-src stays locked down — this only affects
|
||||||
|
# CSS, and nothing here renders untrusted external content into a
|
||||||
|
# style attribute).
|
||||||
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always;
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
try_files $uri $uri/ =404;
|
try_files $uri $uri/ =404;
|
||||||
|
|||||||
Reference in New Issue
Block a user