diff --git a/examples/with-strict-csp/middleware.js b/examples/with-strict-csp/middleware.js index 407d2f0267829..875321f9febf2 100644 --- a/examples/with-strict-csp/middleware.js +++ b/examples/with-strict-csp/middleware.js @@ -4,7 +4,9 @@ export function middleware(request) { const nonce = Buffer.from(crypto.randomUUID()).toString("base64"); const cspHeader = ` default-src 'self'; - script-src 'self' 'nonce-${nonce}' 'strict-dynamic'; + script-src 'self' 'nonce-${nonce}' 'strict-dynamic' https: http: 'unsafe-inline' ${ + process.env.NODE_ENV === "production" ? "" : `'unsafe-eval'` + }; style-src 'self' 'nonce-${nonce}'; img-src 'self' blob: data:; font-src 'self';