diff --git a/app/Http/Middleware/CSPHeader.php b/app/Http/Middleware/CSPHeader.php index 42b53ec2..b5c6ee25 100644 --- a/app/Http/Middleware/CSPHeader.php +++ b/app/Http/Middleware/CSPHeader.php @@ -27,7 +27,7 @@ class CSPHeader ->header( 'Content-Security-Policy', "default-src 'self'; " . - "style-src 'self' cloud.typography.com jonnybarnes.uk; " . + "style-src 'self' 'unsafe-inline' cloud.typography.com jonnybarnes.uk; " . "img-src 'self' data: blob: https://pbs.twimg.com https://jbuk-media.s3-eu-west-1.amazonaws.com https://jbuk-media-dev.s3-eu-west-1.amazonaws.com https://secure.gravatar.com https://graph.facebook.com *.fbcdn.net https://*.cdninstagram.com https://*.4sqi.net https://upload.wikimedia.org; " . "font-src 'self' data:; " . "frame-src 'self' https://www.youtube.com blob:; " . diff --git a/resources/views/master.blade.php b/resources/views/master.blade.php index 28fa3ee3..b6361cb7 100644 --- a/resources/views/master.blade.php +++ b/resources/views/master.blade.php @@ -78,7 +78,7 @@ @section('scripts') - + @show