- Issue created by @fago
- 🇦🇹Austria fago Vienna
it seems the header is set by
modules/lupus_decoupled_responsive_preview/src/EventSubscriber/ContentSecurityEventSubscriber.php - 🇦🇹Austria fago Vienna
ContentSecurityEventSubscriber sets both frame-ancestor and frame-src CSP headers, but only frame-src is necessary to make responsive-toolbar work. the other one seems out of scope and creates this issue. Since there is no reason to set it in this module, imo it's best to remove it.
- 🇦🇹Austria fago Vienna
Successfully tested the MR, it resolves the issue while responsive preview integration still works.
Automatically closed - issue fixed for 2 weeks with no activity.