diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb index 0d17fd4915..64e7a2c157 100644 --- a/config/initializers/content_security_policy.rb +++ b/config/initializers/content_security_policy.rb @@ -16,7 +16,8 @@ "https://www.googletagmanager.com" policy.connect_src :self, GOOGLE_ANALYTICS_DOMAIN, - "https://*.justice.gov.uk" + "https://*.justice.gov.uk", + "http://127.0.0.1:3000" end Rails.application.config.content_security_policy_nonce_generator = ->(request) { request.session.id.to_s } Rails.application.config.content_security_policy_nonce_directives = %w[script-src]