Skip to content

Commit 35197b4

Browse files
AMQ-9739: Removed "upgrade-insecure-requests" from the Web Console's Content-Security-Policy header. (#1472)
Fixes issues loading assets when serving the Web Console via HTTP.
1 parent 23e1030 commit 35197b4

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

assembly/src/release/conf/jetty.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -82,13 +82,13 @@
8282
<bean id="header" class="org.eclipse.jetty.rewrite.handler.HeaderPatternRule">
8383
<property name="pattern" value="*"/>
8484
<property name="name" value="Content-Security-Policy"/>
85-
<property name="value" value="upgrade-insecure-requests; style-src-elem 'self'; style-src 'self'; img-src 'self'; script-src-elem 'self'; default-src 'none'; object-src 'none'; frame-ancestors 'none'; base-uri 'none';" />
85+
<property name="value" value="style-src-elem 'self'; style-src 'self'; img-src 'self'; script-src-elem 'self'; default-src 'none'; object-src 'none'; frame-ancestors 'none'; base-uri 'none';" />
8686
</bean>
8787
<!-- More relaxed rules to allow browsers to properly render XML -->
8888
<bean id="header" class="org.eclipse.jetty.rewrite.handler.HeaderPatternRule">
8989
<property name="pattern" value="/admin/xml/*"/>
9090
<property name="name" value="Content-Security-Policy"/>
91-
<property name="value" value="upgrade-insecure-requests; style-src-elem 'self' 'unsafe-inline'; style-src 'self'; img-src 'self' data:; script-src-elem 'self'; default-src 'none'; object-src 'none'; frame-ancestors 'none'; base-uri 'none';" />
91+
<property name="value" value="style-src-elem 'self' 'unsafe-inline'; style-src 'self'; img-src 'self' data:; script-src-elem 'self'; default-src 'none'; object-src 'none'; frame-ancestors 'none'; base-uri 'none';" />
9292
</bean>
9393
</list>
9494
</property>

0 commit comments

Comments
 (0)