import * as helmet from 'helmet'
-import { CONFIG } from '../initializers/constants'
+import { CONFIG } from '../initializers/config'
const baseDirectives = Object.assign({},
{
connectSrc: ['*', 'data:'],
mediaSrc: ["'self'", 'https:', 'blob:'],
fontSrc: ["'self'", 'data:'],
- imgSrc: ["'self'", 'data:'],
- scriptSrc: ["'self' 'unsafe-inline' 'unsafe-eval'"],
+ imgSrc: ["'self'", 'data:', 'blob:'],
+ scriptSrc: ["'self' 'unsafe-inline' 'unsafe-eval'", 'blob:'],
styleSrc: ["'self' 'unsafe-inline'"],
objectSrc: ["'none'"], // only define to allow plugins, else let defaultSrc 'none' block it
formAction: ["'self'"],