npm package diff
Package: @forge/csp
Versions: 3.4.0 - 3.4.1-next.0
File: package/out/csp/csp-injection-service.js
Index: package/out/csp/csp-injection-service.js
===================================================================
--- package/out/csp/csp-injection-service.js
+++ package/out/csp/csp-injection-service.js
@@ -135,9 +135,8 @@
"'self'",
this.getForgeGlobalCSP(microsEnv, isFedRAMP),
...this.getExistingCSPDetails(types_1.ExternalCspType.STYLE_SRC, existingCSPDetails)
].join(' ');
- const navigateTo = ["'self'"];
return [
`default-src ${defaultSrc}`,
`frame-ancestors ${frameAncestors}`,
`frame-src ${frameSrc}`,
@@ -145,9 +144,8 @@
`img-src ${imgSrc}`,
`media-src ${mediaSrc}`,
`connect-src ${connectSrc}`,
`script-src ${scriptSrc}`,
- `navigate-to ${navigateTo}`,
`style-src ${styleSrc}`,
`form-action 'self'`,
`sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-same-origin allow-scripts`,
`report-uri ${reportUri}`