chore(theseus): add https://*.githubusercontent.com to frame-src (#1298)

* chore: add https://*.githubusercontent.com to frame-src

* chore(app): move `githubusercontent.com` CSP allowance to the proper media category

---------

Co-authored-by: Alejandro González <me@alegon.dev>
Co-authored-by: Prospector <6166773+Prospector@users.noreply.github.com>
This commit is contained in:
ToBinio 2025-05-02 18:53:52 +02:00 committed by GitHub
parent dfef0df464
commit bd0d6a9ac0
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -87,7 +87,8 @@
"img-src": "https: 'unsafe-inline' 'self' asset: http://asset.localhost blob: data:",
"style-src": "'unsafe-inline' 'self'",
"script-src": "https://*.posthog.com 'self'",
"frame-src": "https://www.youtube.com https://www.youtube-nocookie.com https://discord.com 'self'"
"frame-src": "https://www.youtube.com https://www.youtube-nocookie.com https://discord.com 'self'",
"media-src": "https://*.githubusercontent.com"
}
}
}