diff --git a/API/Startup.cs b/API/Startup.cs index e71520dbc..31342e7d9 100644 --- a/API/Startup.cs +++ b/API/Startup.cs @@ -273,7 +273,7 @@ namespace API context.Response.Headers.XFrameOptions = "SAMEORIGIN"; // Setup CSP to ensure we load assets only from these origins - context.Response.Headers.Add("Content-Security-Policy", "default-src 'self' frame-ancestors 'none';"); + context.Response.Headers.Add("Content-Security-Policy", "frame-ancestors 'none';"); await next(); });