diff --git a/Framework/Backend/http/server.js b/Framework/Backend/http/server.js index d17405de9..9d3088b3b 100644 --- a/Framework/Backend/http/server.js +++ b/Framework/Backend/http/server.js @@ -156,6 +156,7 @@ class HttpServer { directives: { /* eslint-disable */ defaultSrc: ["'self'", "data:", hostname + ':*'], + imgSrc: ["'self'", "data:", "blob:"], scriptSrc: ["'self'", ...(allow ? ["'unsafe-eval'"] : [])], styleSrc: ["'self'", "'unsafe-inline'"], connectSrc: ["'self'", 'http://' + hostname + ':' + port, 'https://' + hostname, 'wss://' + hostname, 'ws://' + hostname + ':' + port],