diff --git a/CHANGELOG.md b/CHANGELOG.md index 9fb536dc8..7d58fe8bc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,7 +5,7 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). -## 1.283.0 - 2023-06-24 +## 1.283.1 - 2023-06-24 ### Added diff --git a/apps/api/src/main.ts b/apps/api/src/main.ts index 0d4117a7d..c5940edc7 100644 --- a/apps/api/src/main.ts +++ b/apps/api/src/main.ts @@ -35,7 +35,15 @@ async function bootstrap() { // Support 10mb csv/json files for importing activities app.use(bodyParser.json({ limit: '10mb' })); - app.use(helmet()); + app.use( + helmet({ + contentSecurityPolicy: { + directives: { + scriptSrc: ["'self'", "'unsafe-inline'"] // Allow inline scripts / styles + } + } + }) + ); const BASE_CURRENCY = configService.get('BASE_CURRENCY'); const HOST = configService.get('HOST') || '0.0.0.0'; diff --git a/package.json b/package.json index 3352d27ea..853aaf651 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "ghostfolio", - "version": "1.283.0", + "version": "1.283.1", "homepage": "https://ghostfol.io", "license": "AGPL-3.0", "scripts": {