Skip to content

Commit 9e7742e

Browse files
authored
Fix - 'frame-ancestors' does not support the source expression ''unsafe-inline''
Reference: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors#sources The wrong setting will cause a Chrome console error.
1 parent 8599e3c commit 9e7742e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

app/code/Magento/Csp/etc/config.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@
106106
<frame-ancestors>
107107
<policy_id>frame-ancestors</policy_id>
108108
<self>1</self>
109-
<inline>1</inline>
109+
<inline>0</inline>
110110
<eval>0</eval>
111111
<dynamic>0</dynamic>
112112
</frame-ancestors>
@@ -217,7 +217,7 @@
217217
<frame-ancestors>
218218
<policy_id>frame-ancestors</policy_id>
219219
<self>1</self>
220-
<inline>1</inline>
220+
<inline>0</inline>
221221
<eval>0</eval>
222222
<dynamic>0</dynamic>
223223
</frame-ancestors>

0 commit comments

Comments
 (0)