diff --git a/ansible/roles/schulcloud-client-core/templates/client-configmap-files.yml.j2 b/ansible/roles/schulcloud-client-core/templates/client-configmap-files.yml.j2 index 14ced4a1e3..8585de5f1e 100644 --- a/ansible/roles/schulcloud-client-core/templates/client-configmap-files.yml.j2 +++ b/ansible/roles/schulcloud-client-core/templates/client-configmap-files.yml.j2 @@ -40,7 +40,7 @@ data: // scriptSrc: "'strict-dynamic' 'unsafe-eval' 'nonce-'", scriptSrc: `'self' 'unsafe-eval'`, frameSrc: `'self' https://{{ LIBREOFFICE_PREFIX }}{{ DOMAIN }} https://docs.dbildungscloud.de https://{{ ROCKETCHAT_DNS_PREFIX }}{{ DOMAIN }}`, - frameAncestors: `'self' {{ BETTERMARKS_CSP_URL | default("") }}`, + frameAncestors: `'self' {{ BETTERMARKS_APPS_URL | default("") }}`, // Please activate for production // upgradeInsecureRequestsSrc: 'upgrade-insecure-requests', // blockAllMixedContentSrc: 'block-all-mixed-content', @@ -62,7 +62,7 @@ data: defaultSrc: 'https://www10-fms.hpi.uni-potsdam.de https://cloud-instances.s3.hidrive.strato.com', }, '^/courses': { - defaultSrc: 'https://nexboard.nexenio.com https://lti.tools https://codeocean.openhpi.de https://acc.bettermarks.com https://moodle.hpi-schul-cloud.de', + defaultSrc: 'https://nexboard.nexenio.com https://lti.tools https://codeocean.openhpi.de {{ BETTERMARKS_SCHOOL_URL | default("") }} https://moodle.hpi-schul-cloud.de', fontSrc: 'https://vjs.zencdn.net https://fonts.googleapis.com https://cdn.jsdelivr.net', styleSrc: 'https://vjs.zencdn.net', frameSrc: 'https://nexboard.nexenio.com',