From a746a21de2bb9d324e2cbda7d76b4a8a6391f829 Mon Sep 17 00:00:00 2001 From: Sparsh Sam <110058692+sparshsam@users.noreply.github.com> Date: Sun, 28 Jun 2026 01:21:54 -0400 Subject: [PATCH] fix CSP: add walletconnect pulse + web3modal endpoints to connect-src - Add https://pulse.walletconnect.org (WalletConnect telemetry) - Add https://api.web3modal.org (Reown project config API) - Change COOP from same-origin to same-origin-allow-popups (Base Account SDK requirement) --- vercel.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/vercel.json b/vercel.json index ac009fc..5e1ff7c 100644 --- a/vercel.json +++ b/vercel.json @@ -7,7 +7,7 @@ "headers": [ { "key": "Content-Security-Policy", - "value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https://sepolia.base.org https://*.walletconnect.com wss://*.walletconnect.com https://*.reown.com wss://*.reown.com https://*.basescan.org; frame-src 'self' https://*.walletconnect.com https://*.reown.com; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests" + "value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https://sepolia.base.org https://pulse.walletconnect.org https://api.web3modal.org https://*.walletconnect.com wss://*.walletconnect.com https://*.reown.com wss://*.reown.com https://*.basescan.org; frame-src 'self' https://*.walletconnect.com https://*.reown.com; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests" }, { "key": "X-Frame-Options", @@ -31,7 +31,7 @@ }, { "key": "Cross-Origin-Opener-Policy", - "value": "same-origin" + "value": "same-origin-allow-popups" }, { "key": "Cross-Origin-Resource-Policy",