Skip to content

Commit 1716b9f

Browse files
authored
fix: swagger UI CSP error (#25368)
1 parent a4d8f36 commit 1716b9f

File tree

3 files changed

+4
-4
lines changed

3 files changed

+4
-4
lines changed

requirements/base.txt

+1-1
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@ flask==2.2.5
9696
# flask-migrate
9797
# flask-sqlalchemy
9898
# flask-wtf
99-
flask-appbuilder==4.3.6
99+
flask-appbuilder==4.3.7
100100
# via apache-superset
101101
flask-babel==1.0.0
102102
# via flask-appbuilder

setup.py

+1-1
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ def get_git_sha() -> str:
8484
"cryptography>=41.0.2, <41.1.0",
8585
"deprecation>=2.1.0, <2.2.0",
8686
"flask>=2.2.5, <3.0.0",
87-
"flask-appbuilder>=4.3.6, <5.0.0",
87+
"flask-appbuilder>=4.3.7, <5.0.0",
8888
"flask-caching>=1.11.1, <2.0",
8989
"flask-compress>=1.13, <2.0",
9090
"flask-talisman>=1.0.0, <2.0",

superset/config.py

+2-2
Original file line numberDiff line numberDiff line change
@@ -1429,7 +1429,7 @@ def EMAIL_HEADER_MUTATOR( # pylint: disable=invalid-name,unused-argument
14291429
"style-src": ["'self'", "'unsafe-inline'"],
14301430
"script-src": ["'self'", "'strict-dynamic'"],
14311431
},
1432-
"content_security_policy_nonce_in": ["script-src"],
1432+
"content_security_policy_nonce_in": ["script-src", "style-src"],
14331433
"force_https": False,
14341434
}
14351435
# React requires `eval` to work correctly in dev mode
@@ -1447,7 +1447,7 @@ def EMAIL_HEADER_MUTATOR( # pylint: disable=invalid-name,unused-argument
14471447
"style-src": ["'self'", "'unsafe-inline'"],
14481448
"script-src": ["'self'", "'unsafe-inline'", "'unsafe-eval'"],
14491449
},
1450-
"content_security_policy_nonce_in": ["script-src"],
1450+
"content_security_policy_nonce_in": ["script-src", "style-src"],
14511451
"force_https": False,
14521452
}
14531453

0 commit comments

Comments
 (0)