Fix: CSP blockierte Kartenkacheln - img-src um Tile-Server erweitert

- img-src erlaubt jetzt *.basemaps.cartocdn.com (Dark-Theme)
  und *.tile.openstreetmap.org (Light-Theme)
- Das war die Ursache fuer die graue Karte ohne Hintergrund

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Dieser Commit ist enthalten in:
claude-dev
2026-03-04 22:54:54 +01:00
Ursprung 17d2e097a6
Commit 0920d218f5

Datei anzeigen

@@ -235,7 +235,7 @@ class SecurityHeadersMiddleware(BaseHTTPMiddleware):
"script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; " "script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; "
"style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; " "style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; "
"font-src 'self' https://fonts.gstatic.com; " "font-src 'self' https://fonts.gstatic.com; "
"img-src 'self' data:; " "img-src 'self' data: https://*.basemaps.cartocdn.com https://*.tile.openstreetmap.org; "
"connect-src 'self' wss: ws:; " "connect-src 'self' wss: ws:; "
"frame-ancestors 'none'" "frame-ancestors 'none'"
) )