diff --git a/lib/csp.js b/lib/csp.js index b343ea011..c54007646 100644 --- a/lib/csp.js +++ b/lib/csp.js @@ -8,7 +8,7 @@ const defaultDirectives = { baseUri: ['\'self\''], connectSrc: ['\'self\''], fontSrc: ['\'self\''], - frameSrc: ['https://player.vimeo.com', 'https://www.slideshare.net/slideshow/embed_code/key/', 'https://www.youtube.com'], + frameSrc: ['\'self\'', 'https://player.vimeo.com', 'https://www.slideshare.net/slideshow/embed_code/key/', 'https://www.youtube.com'], imgSrc: ['*'], // we allow using arbitrary images scriptSrc: [ config.serverURL + '/build/',