diff --git a/app/Http/Middleware/SecureHeaders.php b/app/Http/Middleware/SecureHeaders.php index cdc3f1b24e..5c34953fdd 100644 --- a/app/Http/Middleware/SecureHeaders.php +++ b/app/Http/Middleware/SecureHeaders.php @@ -55,7 +55,7 @@ class SecureHeaders "base-uri 'self'", "font-src 'self' data:", sprintf("connect-src 'self' %s", $trackingScriptSrc), - sprintf("img-src 'strict-dynamic' %s", $trackingScriptSrc), + sprintf("img-src 'strict-dynamic' 'self' %s", $trackingScriptSrc), "manifest-src 'self'", ];