diff --git a/package.json b/package.json index 89925a45c33..b83391cf75c 100644 --- a/package.json +++ b/package.json @@ -111,7 +111,7 @@ "react-router": "^1.0.0", "react-router-bootstrap": "https://github.com/FreeCodeCamp/react-router-bootstrap.git#freecodecamp", "react-toastr": "^2.3.0", - "react-vimeo": "~0.0.3", + "react-vimeo": "~0.1.0", "request": "^2.65.0", "rev-del": "^1.0.5", "rx": "^4.0.0", diff --git a/server/middlewares/csp.js b/server/middlewares/csp.js index 21e542dd017..2aaac24d18d 100644 --- a/server/middlewares/csp.js +++ b/server/middlewares/csp.js @@ -24,7 +24,8 @@ export default function csp() { 'https://*.jsdelivr.com', '*.jsdelivr.com', '*.twimg.com', - 'https://*.twimg.com' + 'https://*.twimg.com', + 'vimeo.com' ].concat(trusted), connectSrc: [ 'vimeo.com'