diff --git a/packages/core/src/middleware/koa-security-headers.ts b/packages/core/src/middleware/koa-security-headers.ts index 03c95b754..3cb494feb 100644 --- a/packages/core/src/middleware/koa-security-headers.ts +++ b/packages/core/src/middleware/koa-security-headers.ts @@ -106,7 +106,13 @@ export default function koaSecurityHeaders( "'self'", ...conditionalArray(!isProduction && ["'unsafe-eval'", "'unsafe-inline'"]), ], - connectSrc: ["'self'", ...adminOrigins, ...coreOrigins, ...developmentOrigins], + connectSrc: [ + "'self'", + ...adminOrigins, + ...coreOrigins, + ...developmentOrigins, + ...appInsightsOrigins, + ], // Allow Main Flow origin loaded in preview iframe frameSrc: ["'self'", ...adminOrigins, ...coreOrigins], }, diff --git a/packages/ui/src/index.html b/packages/ui/src/index.html index 8df3f2db5..7cdd85d13 100644 --- a/packages/ui/src/index.html +++ b/packages/ui/src/index.html @@ -5,8 +5,24 @@ - - + +