diff --git a/api/nginx.conf b/api/nginx.conf index 29646c8eb..3241eab46 100644 --- a/api/nginx.conf +++ b/api/nginx.conf @@ -34,7 +34,7 @@ http { set $IMG "img-src 'self' data: *.API_URL"; set $FONT "font-src 'self' data:"; set $WORKER "worker-src 'self' blob:"; - set $STYLE_SRC_ELEM "style-src 'self'"; + set $STYLE_SRC_ELEM "style-src-elem 'self' 'unsafe-inline'"; set $STYLE_SRC_ATTR "style-src-attr 'unsafe-inline'"; set $CONNECT "connect-src 'self' *.API_URL:* *.ROOT_URL:*"; add_header 'Content-Security-Policy' "default-src 'self' *.API_URL; ${IMG}; ${WORKER}; ${CONNECT}; ${STYLE_SRC_ATTR}; ${STYLE_SRC_ELEM}; ${FONT}; upgrade-insecure-requests;" always;