diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index 63bc18e1e0b..e191b7f1da0 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -22,6 +22,7 @@ :font_src => ["'self'", 'https://fonts.gstatic.com', "https://fonts.googleapis.com"], :frame_src => ["'self'"], :img_src => ["'self'", "data:"], + :object_src => ["'self'"], :script_src => ["'unsafe-eval'", "'unsafe-inline'", "'self'"], :style_src => ["'unsafe-inline'", "'self'", "https://fonts.googleapis.com", "https://fonts.gstatic.com"], }