diff --git a/services/web/app/src/infrastructure/CSP.mjs b/services/web/app/src/infrastructure/CSP.mjs index eb16282c9d..1f9b49d0b9 100644 --- a/services/web/app/src/infrastructure/CSP.mjs +++ b/services/web/app/src/infrastructure/CSP.mjs @@ -85,7 +85,7 @@ const buildViewPolicy = ( viewDirectives ) => { const directives = [ - `script-src 'nonce-${scriptNonce}' 'unsafe-inline' 'strict-dynamic' https: 'report-sample'`, // only allow scripts from certain sources + `script-src 'nonce-${scriptNonce}' 'unsafe-inline' 'strict-dynamic' 'wasm-unsafe-eval' https: 'report-sample'`, // only allow scripts from certain sources `object-src 'none'`, // forbid loading an "object" element `base-uri 'none'`, // forbid setting a "base" element ...(viewDirectives ?? []),