Coursemology/coursemology2

Can no longer change profile picture due to Content-Security-Policy

Nafeij opened this issue · 1 comments

Nafeij commented

There is a bug which prevents users from changing their profile picture.

On Firefox:

Content-Security-Policy: The page’s settings blocked the loading of a resource at blob:https://coursemology.org/c2ae4d9e-9cc2-40e1-acee-0e50374f3765 (“img-src”).

image

On Chrome:

Refused to load the image 'blob:https://coursemology.org/ae047b93-91ef-46f0-9db0-fb9504a618d0' because it violates the following Content Security Policy directive: "img-src https: data:".

image

Thanks for reporting Jiefan, the Content Security Policy has been updated to allow blob: now.