fix(api): 🚑 Fix incorrect Content-Security-Policy on frontend

This commit is contained in:
Jesse Wierzbinski 2024-05-02 13:57:36 -10:00
parent 7a90abeaec
commit 74b9083551
No known key found for this signature in database

View file

@ -32,7 +32,7 @@ export const clientResponse = (
) => { ) => {
return response(data, status, { return response(data, status, {
"Content-Security-Policy": "Content-Security-Policy":
"Content-Security-Policy: default-src 'none'; script-src 'self'; style-src 'self'; img-src *; font-src 'self'; connect-src 'self'; media-src *; object-src 'none'; prefetch-src 'none'; child-src 'none'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'", "default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src *; font-src 'self'; connect-src 'self'; media-src *; object-src 'none'; prefetch-src 'none'; child-src 'none'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'",
"Access-Control-Allow-Origin": "null", "Access-Control-Allow-Origin": "null",
...headers, ...headers,
}); });