Add vimeo as allowed frame-src for introductional video (#6227)

[ci skip]
pull/6230/head
Wieland Lindenthal 7 years ago committed by Oliver Günther
parent a76b5d2119
commit a6f88f552f
  1. 2
      config/initializers/secure_headers.rb

@ -17,7 +17,7 @@ SecureHeaders::Configuration.default do |config|
assets_src << asset_host if asset_host.present?
# Valid for iframes
frame_src = ["'self'"]
frame_src = %w['self' https://player.vimeo.com]
# Allow in-context translations iframe and sources if enabled
if OpenProject::Configuration.crowdin_in_context_translations?

Loading…
Cancel
Save