Set correct mime type in jailed. Set correct types on script imports in bonfire/show. Open helmet up to potentially unsafe levels by allowing "* unsafe-inline" in scriptSrc.
This commit is contained in:
@@ -1 +1 @@
|
||||
<script src="_frame.js"></script>
|
||||
<script sandbox="allow-same-origin allow-scripts" src="_frame.js"></script>
|
||||
|
Reference in New Issue
Block a user