diff --git a/app/Http/Middleware/AddContentSecurityPolicy.php b/app/Http/Middleware/AddContentSecurityPolicy.php index 8c911a5..b97f455 100644 --- a/app/Http/Middleware/AddContentSecurityPolicy.php +++ b/app/Http/Middleware/AddContentSecurityPolicy.php @@ -24,9 +24,8 @@ class AddContentSecurityPolicy "style-src 'self' 'unsafe-inline' http: https:; " . "connect-src 'self' ws: http: https:;"; } else { - // Production CSP - Livewire v3 requires unsafe-eval and nonce for inline scripts - $nonce = csp_nonce(); - $csp = "script-src 'self' 'unsafe-eval' 'nonce-{$nonce}' https:; " . + // Production CSP - Livewire v3 requires unsafe-eval and unsafe-inline + $csp = "script-src 'self' 'unsafe-eval' 'unsafe-inline' https:; " . "style-src 'self' 'unsafe-inline' https:; " . "connect-src 'self' https:;"; }