invidious/assets/js/global.js
Leon Klingele 9219038469
Migrate to a good Content Security Policy
So attacks such as XSS (see [0]) will no longer be of an issue.

[0]: https://github.com/omarroth/invidious/issues/1022
2020-03-11 21:07:45 +09:00

4 lines
262 B
JavaScript

// Disable Web Workers. Fixes Video.js CSP violation (created by `new Worker(objURL)`):
// Refused to create a worker from 'blob:http://host/id' because it violates the following Content Security Policy directive: "worker-src 'self'".
window.Worker = undefined;