From 440093b30ad607dcc431d353313ab97ab440e903 Mon Sep 17 00:00:00 2001
From: Jed Fox <git@jedfox.com>
Date: Fri, 31 Mar 2023 12:28:34 -0500
Subject: [PATCH] Allow `data:` URLs for images in Netlify deploys (#832)

---
 packages/desktop-client/public/_headers | 4 ++--
 upcoming-release-notes/832.md           | 6 ++++++
 2 files changed, 8 insertions(+), 2 deletions(-)
 create mode 100644 upcoming-release-notes/832.md

diff --git a/packages/desktop-client/public/_headers b/packages/desktop-client/public/_headers
index ca84ccb1f..867c3188e 100644
--- a/packages/desktop-client/public/_headers
+++ b/packages/desktop-client/public/_headers
@@ -1,10 +1,10 @@
 /*
   Cross-Origin-Opener-Policy: same-origin
   Cross-Origin-Embedder-Policy: require-corp
-  Content-Security-Policy: default-src 'self' blob:; script-src 'self' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; connect-src http: https:;
+  Content-Security-Policy: default-src 'self' blob:; img-src 'self' blob: data:; script-src 'self' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; connect-src http: https:;
 
 /kcab/*
-  Content-Security-Policy: default-src 'self' blob:; script-src 'self' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; connect-src http: https:;
+  Content-Security-Policy: default-src 'self' blob:; img-src 'self' blob: data:; script-src 'self' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline'; connect-src http: https:;
 
 /*.wasm
   Content-Type: application/wasm
diff --git a/upcoming-release-notes/832.md b/upcoming-release-notes/832.md
new file mode 100644
index 000000000..fdee61952
--- /dev/null
+++ b/upcoming-release-notes/832.md
@@ -0,0 +1,6 @@
+---
+category: Maintenance
+authors: [j-f1]
+---
+
+Allow `data:` URLs for images in Netlify deploys
-- 
GitLab