diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index a7900165f9b..f805ff60a33 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -46,6 +46,10 @@ default_csp_config[:script_src] = ["'self'", "'unsafe-eval'"] if !Rails.env.production? + if IdentityConfig.store.rails_mailer_previews_enabled + default_csp_config[:style_src] << "'unsafe-inline'" + end + config.csp = default_csp_config if ENV['WEBPACK_PORT']