diff --git a/src/Security/ContentSecurityPolicyHandler.php b/src/Security/ContentSecurityPolicyHandler.php index 38d47a659..7744f4794 100644 --- a/src/Security/ContentSecurityPolicyHandler.php +++ b/src/Security/ContentSecurityPolicyHandler.php @@ -79,7 +79,7 @@ public function configureOptions(OptionsResolver $resolver): void self::DEFAULT_OPT => self::SELF, self::IMG_OPT => '* data: blob:', self::MEDIA_OPT => self::SELF . ' data:', - self::SCRIPT_OPT => self::SELF . " 'nonce-" . $this->getNonce() . "' 'unsafe-inline' 'unsafe-eval'", + self::SCRIPT_OPT => self::SELF . " 'nonce-" . $this->getNonce() . "' 'unsafe-eval'", self::STYLE_OPT => self::SELF . " 'unsafe-inline'", self::FRAME_OPT => self::SELF . ' data:', self::FRAME_ANCHESTORS => self::SELF,