From 3d37f62c51077d4d4648eb30e1a8aabdd6cdc5fd Mon Sep 17 00:00:00 2001 From: rash Date: Tue, 3 Feb 2026 10:34:52 +0100 Subject: [PATCH] better syntax for cors header setting --- src/pretix/base/middleware.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/pretix/base/middleware.py b/src/pretix/base/middleware.py index a73f065fca..e3d6086f84 100644 --- a/src/pretix/base/middleware.py +++ b/src/pretix/base/middleware.py @@ -280,11 +280,11 @@ class SecurityMiddleware(MiddlewareMixin): h = { 'default-src': ["{static}"], - 'script-src': ["{static}", "http://localhost:5173", "ws://localhost:5173"] if settings.VITE_DEV_MODE else ["{static}"], + 'script-src': ["{static}"] + (["http://localhost:5173", "ws://localhost:5173"] if settings.VITE_DEV_MODE else []), 'object-src': ["'none'"], 'frame-src': ['{static}'], 'style-src': ["{static}", "{media}"], - 'connect-src': ["{dynamic}", "{media}", "ws://localhost:5173" if settings.VITE_DEV_MODE else ""], + 'connect-src': ["{dynamic}", "{media}"] + (["http://localhost:5173", "ws://localhost:5173"] if settings.VITE_DEV_MODE else []), 'img-src': ["{static}", "{media}", "data:"] + img_src, 'font-src': ["{static}"] + list(font_src), 'media-src': ["{static}", "data:"],