From 8c936a91becd8d707314172f3993026adf991ddc Mon Sep 17 00:00:00 2001 From: morihoos <61077785+morihoos@users.noreply.github.com> Date: Thu, 8 Feb 2024 17:41:33 +0100 Subject: [PATCH] fix(csp): remove illegal characters in directive names (#1585) --- packages/backend/src/helpers/web-ui-handler.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/backend/src/helpers/web-ui-handler.js b/packages/backend/src/helpers/web-ui-handler.js index c5bd4f35..a20c66ba 100644 --- a/packages/backend/src/helpers/web-ui-handler.js +++ b/packages/backend/src/helpers/web-ui-handler.js @@ -15,7 +15,7 @@ const webUIHandler = async (app) => { app.use(express.static(webBuildPath)); app.get('*', (_req, res) => { - res.set('Content-Security-Policy', 'frame-ancestors: none;'); + res.set('Content-Security-Policy', 'frame-ancestors \'none\';'); res.set('X-Frame-Options', 'DENY'); res.sendFile(indexHtml);