From 79c58d7144683e637c6edfa95f560d131a6e26be Mon Sep 17 00:00:00 2001 From: SITO Date: Sat, 9 May 2026 00:44:12 +0200 Subject: [PATCH] fix(csp): permitir scripts/estilos inline para que funcione mobile-ui MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit El CSP antes era 'script-src self http://localhost:3000/js' lo cual bloqueaba el script inline que inyectamos para la paginación móvil de mode-buttons. Esto explicaba por qué las flechas no aparecían aunque la APK tuviera el código correcto. Co-Authored-By: Claude Sonnet 4.6 --- nodejs-project/nodejs-project/src/client/middleware.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nodejs-project/nodejs-project/src/client/middleware.js b/nodejs-project/nodejs-project/src/client/middleware.js index 03d9d1d7..4bfe22ae 100644 --- a/nodejs-project/nodejs-project/src/client/middleware.js +++ b/nodejs-project/nodejs-project/src/client/middleware.js @@ -73,8 +73,8 @@ module.exports = ({ host, port, middleware, allowHost }) => { const csp = [ "default-src 'self'", - "script-src 'self' http://localhost:3000/js", - "style-src 'self'", + "script-src 'self' 'unsafe-inline' http://localhost:3000/js", + "style-src 'self' 'unsafe-inline'", "img-src 'self'", "media-src 'self' blob:", "worker-src 'self' blob:",