How to set specific Content-Security-Policy in Ruby on Rails

Viewed 729

Hey I have an Ror App and I've set the CSP in my app globaly this is CSP file in my config/initilaizers/content_security_policy

Rails.application.config.content_security_policy do |policy|
  policy.default_src :self, :https
  policy.font_src    :self, :https, :data
  policy.img_src     :self, :https, :data
  policy.object_src  :none
  policy.script_src  :self, :https
  policy.style_src   :self, :https
end

but I have a problem with ckeditor and google font

1st google font wont loaded the font

2nd ckeditor have an error on the style like this

ckeditor.js:94 Refused to apply inline style because it violates the following Content Security Policy directive: "style-src 'self' https:". Either the 'unsafe-inline' keyword, a hash ('sha256-ZVjd2zfSTfAVh1y7eCcNk0SPGUQOP/H8vzrFJIVgg90='), or a nonce ('nonce-...') is required to enable inline execution.

the question is, can I add specific unsafe_inline only for ckeditor CSP ? this is because I only use this CKEditor only in rails_admin

and why the google font wont loaded after I generated integrity hash?

thanks

0 Answers
Related