mirror of
https://github.com/versia-pub/server.git
synced 2025-12-06 16:38:19 +01:00
fix(frontend): 🐛 Add unsafe-inline to CSP for frontend
This commit is contained in:
parent
74b9083551
commit
a339b7fa94
|
|
@ -32,7 +32,7 @@ export const clientResponse = (
|
|||
) => {
|
||||
return response(data, status, {
|
||||
"Content-Security-Policy":
|
||||
"default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src *; font-src 'self'; connect-src 'self'; media-src *; object-src 'none'; prefetch-src 'none'; child-src 'none'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'",
|
||||
"default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; font-src 'self'; connect-src 'self'; media-src *; object-src 'none'; prefetch-src 'none'; child-src 'none'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'",
|
||||
"Access-Control-Allow-Origin": "null",
|
||||
...headers,
|
||||
});
|
||||
|
|
|
|||
Loading…
Reference in a new issue