Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[5.x] Fix: Include port in CSP for Live Preview #11498

Merged
merged 5 commits into from
Feb 25, 2025

Conversation

dmxmo
Copy link
Contributor

@dmxmo dmxmo commented Feb 25, 2025

This fixes #11497 where Live Preview's Content Security Policy (CSP) does not include the port number in the frame-ancestors directive when determining allowed origins.

This issue affects configurations where the control panel is served on a custom port (e.g., http://127.0.0.1:8000/ or http://localhost:8080/). Since CSP treats http://127.0.0.1/ and http://127.0.0.1:8000/ as distinct origins, the live preview fails to load within an iframe.

@jasonvarga jasonvarga merged commit 7f8ec82 into statamic:5.x Feb 25, 2025
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Live Preview CSP rule does not include port number
3 participants