From 518298f71c79e04b555d9960aeadd5dd0fd988b2 Mon Sep 17 00:00:00 2001 From: Martin Gross Date: Wed, 12 Dec 2018 08:59:22 +0100 Subject: [PATCH] Add media-src CSP to middleware (#1121) --- src/pretix/base/middleware.py | 1 + 1 file changed, 1 insertion(+) diff --git a/src/pretix/base/middleware.py b/src/pretix/base/middleware.py index a2f1fedf2..fb3a21be1 100644 --- a/src/pretix/base/middleware.py +++ b/src/pretix/base/middleware.py @@ -189,6 +189,7 @@ class SecurityMiddleware(MiddlewareMixin): 'connect-src': ["{dynamic}", "{media}", "https://checkout.stripe.com"], 'img-src': ["{static}", "{media}", "data:", "https://*.stripe.com"], 'font-src': ["{static}"], + 'media-src': ["{static}", "data:"], # form-action is not only used to match on form actions, but also on URLs # form-actions redirect to. In the context of e.g. payment providers or # single-sign-on this can be nearly anything so we cannot really restrict