fix: remove CSP headers causing ERR_BLOCKED_BY_ORB (v0.6.9)
Some checks failed
Deploy quoter Microservice on push / deploy (push) Has been cancelled

- Remove Content-Security-Policy that blocked cross-origin image loading
- Remove X-Frame-Options: DENY (too strict for file CDN)
- Remove X-XSS-Protection (deprecated header)
- Keep minimal security headers: nosniff, Referrer-Policy, HSTS
- CORS now works without conflicts for browser image requests
This commit is contained in:
2025-10-04 08:55:39 +03:00
parent 9d68c0c078
commit 826172e8d2
6 changed files with 32 additions and 24 deletions

22
Cargo.lock generated
View File

@@ -392,9 +392,9 @@ checksum = "ace50bade8e6234aa140d9a2f552bbee1db4d353f69b8217bc503490fc1a9f26"
[[package]]
name = "aws-config"
version = "1.8.6"
version = "1.8.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8bc1b40fb26027769f16960d2f4a6bc20c4bb755d403e552c8c1a73af433c246"
checksum = "04b37ddf8d2e9744a0b9c19ce0b78efe4795339a90b66b7bae77987092cd2e69"
dependencies = [
"aws-credential-types",
"aws-runtime",
@@ -417,9 +417,9 @@ dependencies = [
[[package]]
name = "aws-credential-types"
version = "1.2.6"
version = "1.2.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d025db5d9f52cbc413b167136afb3d8aeea708c0d8884783cf6253be5e22f6f2"
checksum = "799a1290207254984cb7c05245111bc77958b92a3c9bb449598044b36341cce6"
dependencies = [
"aws-smithy-async",
"aws-smithy-runtime-api",
@@ -452,9 +452,9 @@ dependencies = [
[[package]]
name = "aws-runtime"
version = "1.5.10"
version = "1.5.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c034a1bc1d70e16e7f4e4caf7e9f7693e4c9c24cd91cf17c2a0b21abaebc7c8b"
checksum = "2e1ed337dabcf765ad5f2fb426f13af22d576328aaf09eac8f70953530798ec0"
dependencies = [
"aws-credential-types",
"aws-sigv4",
@@ -477,9 +477,9 @@ dependencies = [
[[package]]
name = "aws-sdk-s3"
version = "1.106.0"
version = "1.107.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2c230530df49ed3f2b7b4d9c8613b72a04cdac6452eede16d587fc62addfabac"
checksum = "adb9118b3454ba89b30df55931a1fa7605260fc648e070b5aab402c24b375b1f"
dependencies = [
"aws-credential-types",
"aws-runtime",
@@ -511,9 +511,9 @@ dependencies = [
[[package]]
name = "aws-sdk-sts"
version = "1.85.0"
version = "1.87.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "410309ad0df4606bc721aff0d89c3407682845453247213a0ccc5ff8801ee107"
checksum = "5871bec9a79a3e8d928c7788d654f135dde0e71d2dd98089388bab36b37ef607"
dependencies = [
"aws-credential-types",
"aws-runtime",
@@ -2890,7 +2890,7 @@ dependencies = [
[[package]]
name = "quoter"
version = "0.6.8"
version = "0.6.9"
dependencies = [
"actix",
"actix-cors",