Skip to content
This repository was archived by the owner on Sep 24, 2024. It is now read-only.

Commit d954817

Browse files
committed
yet more csp
1 parent 1ffa412 commit d954817

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

middleware/headers.js

+1-1
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
.setHeader('X-Repository-License', 'Affero General Public License v3.0 or newer (AGPL-3.0-or-later)')
77
.setHeader('X-OS', os == 'win32' ? 'Windows' : os == 'linux' ? 'Linux' : os == 'darwin' ? 'MacOS' : 'Other')
88
.setHeader('X-Node-Version', v.node)
9-
.setHeader('Content-Security-Policy', "default-src *; script-src 'self' google.com *.google.com *.googlesyndication.com googlesyndication.com *.googleadservices.com googleadservices.com *.corbado.io corbado.io *.sentry-cdn.com sentry-cdn.com blob: 'unsafe-inline'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.thefemdevs.com; img-src *; font-src *; connect-src *; media-src *; object-src 'none';frame-ancestors *; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self'; manifest-src 'self'; require-trusted-types-for 'script';")
9+
.setHeader('Content-Security-Policy', "default-src *; script-src 'self' google.com *.google.com *.googlesyndication.com googlesyndication.com *.googleadservices.com googleadservices.com *.corbado.io corbado.io *.sentry-cdn.com sentry-cdn.com *.thefemdevs.com blob: 'unsafe-inline'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.thefemdevs.com; img-src *; font-src *; connect-src *; media-src *; object-src 'none';frame-ancestors *; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self'; manifest-src 'self'; require-trusted-types-for 'script';")
1010
.setHeader('Cross-Origin-Opener-Policy', 'same-origin')
1111
.setHeader('Cross-Origin-Embedder-Policy', 'require-corp')
1212
.setHeader('Cross-Origin-Resource-Policy', 'cross-origin')

0 commit comments

Comments
 (0)