diff --git a/api/nginx.conf b/api/nginx.conf index 7c73bc1e2..0fe5bfeb3 100644 --- a/api/nginx.conf +++ b/api/nginx.conf @@ -30,7 +30,7 @@ http { add_header 'Referrer-Policy' 'strict-origin-when-cross-origin' always; add_header 'Strict-Transport-Security' 'max-age=31536000; includeSubDomains; preload' always; add_header 'Permissions-Policy' 'fullscreen=(self), geolocation=(self), clipboard-read=(self), clipboard-write=(self)' always; - add_header 'Content-Security-Policy' "default-src 'self'; img-src 'self' data:; upgrade-insecure-requests;" always; + add_header 'Content-Security-Policy' "default-src 'self'; img-src 'self' data:; worker-src 'self' blob:; upgrade-insecure-requests;" always; location / { if ($request_uri ~ ^/(.*)\.html) {