diff --git a/requirements/base.txt b/requirements/base.txt index 4b420f4ee9d9..3370eceac4a6 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -96,7 +96,7 @@ flask==2.2.5 # flask-migrate # flask-sqlalchemy # flask-wtf -flask-appbuilder==4.3.6 +flask-appbuilder==4.3.7 # via apache-superset flask-babel==1.0.0 # via flask-appbuilder diff --git a/setup.py b/setup.py index 79649c016721..6190eaf65c78 100644 --- a/setup.py +++ b/setup.py @@ -84,7 +84,7 @@ def get_git_sha() -> str: "cryptography>=41.0.2, <41.1.0", "deprecation>=2.1.0, <2.2.0", "flask>=2.2.5, <3.0.0", - "flask-appbuilder>=4.3.6, <5.0.0", + "flask-appbuilder>=4.3.7, <5.0.0", "flask-caching>=1.11.1, <2.0", "flask-compress>=1.13, <2.0", "flask-talisman>=1.0.0, <2.0", diff --git a/superset/config.py b/superset/config.py index 74f5df0e6e20..e255fa5401bf 100644 --- a/superset/config.py +++ b/superset/config.py @@ -1429,7 +1429,7 @@ def EMAIL_HEADER_MUTATOR( # pylint: disable=invalid-name,unused-argument "style-src": ["'self'", "'unsafe-inline'"], "script-src": ["'self'", "'strict-dynamic'"], }, - "content_security_policy_nonce_in": ["script-src"], + "content_security_policy_nonce_in": ["script-src", "style-src"], "force_https": False, } # React requires `eval` to work correctly in dev mode @@ -1447,7 +1447,7 @@ def EMAIL_HEADER_MUTATOR( # pylint: disable=invalid-name,unused-argument "style-src": ["'self'", "'unsafe-inline'"], "script-src": ["'self'", "'unsafe-inline'", "'unsafe-eval'"], }, - "content_security_policy_nonce_in": ["script-src"], + "content_security_policy_nonce_in": ["script-src", "style-src"], "force_https": False, }