From cc2b9d476f90391b69865046ef9feeb336438ecf Mon Sep 17 00:00:00 2001 From: Kevin Veen-Birkenbach Date: Wed, 17 Sep 2025 02:47:01 +0200 Subject: [PATCH] Added blob csp rule for xwiki --- roles/web-app-xwiki/config/main.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/roles/web-app-xwiki/config/main.yml b/roles/web-app-xwiki/config/main.yml index 6d987eae..2b374839 100644 --- a/roles/web-app-xwiki/config/main.yml +++ b/roles/web-app-xwiki/config/main.yml @@ -24,7 +24,9 @@ features: ldap: false # Just OIDC or LDAP can be enabled server: csp: - whitelist: {} + whitelist: + worker-src: + - "blob:" flags: script-src: unsafe-eval: true