just had a problem attaching to toots in my instance. it always said "Oops! An unexpected error occurred."
turned out, that my rule prohibited `blob:` images.

now it's running fine with

add_header Content-Security-Policy "default-src 'self' 'unsafe-inline'; img-src 'self' data: blob:";

