From 1172ba20ec93ae97aa0d9c678ac115b2eb4e046e Mon Sep 17 00:00:00 2001 From: Daniel Nitsikopoulos Date: Sun, 4 Feb 2024 20:24:26 +1100 Subject: [PATCH] Add youtube-nocookie as an allowed embed source --- config/app.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/app.rb b/config/app.rb index 9d6f744..de88bb7 100644 --- a/config/app.rb +++ b/config/app.rb @@ -16,7 +16,7 @@ module Adamantium config.actions.content_security_policy[:script_src] += " https://unpkg.com/@highlightjs/cdn-assets@11.8.0/highlight.min.js" config.actions.content_security_policy[:connect_src] += " https://stats.dnitza.com/api/event https://*.mapbox.com" - config.actions.content_security_policy[:frame_src] += " https://embed.music.apple.com https://www.youtube.com https://player.vimeo.com" + config.actions.content_security_policy[:frame_src] += " https://embed.music.apple.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com" config.actions.content_security_policy[:style_src] += " https://api.mapbox.com/mapbox-gl-js/v2.9.1/mapbox-gl.css" config.actions.content_security_policy[:style_src] += " https://unpkg.com/@highlightjs/cdn-assets@11.8.0/styles/github-dark.min.css" config.actions.content_security_policy[:child_src] = " blob:"