diff --git a/server.js b/server.js index fcb4872..931f3b3 100644 --- a/server.js +++ b/server.js @@ -79,7 +79,7 @@ app.use(function(req, res, next) { res.set('Strict-Transport-Security', 'max-age=16070400; includeSubDomains'); // CSP var iframe = development ? "http://" + req.hostname + ":" + port : "https://" + req.hostname; // allow iframe to load assets - res.set('Content-Security-Policy', "default-src 'self' " + iframe + "; object-src 'none'; connect-src *; style-src 'self' 'unsafe-inline' " + iframe + "; img-src 'self' data:"); + res.set('Content-Security-Policy', "default-src 'self' " + iframe + "; object-src 'none'; connect-src *; style-src 'self' 'unsafe-inline' " + iframe + "; img-src *"); // set Cache-control Header (for AppCache) res.set('Cache-control', 'public, max-age=0'); next(); diff --git a/src/index.html b/src/index.html index 0771090..d0a577f 100644 --- a/src/index.html +++ b/src/index.html @@ -5,7 +5,7 @@ Whiteout Mail - +