CSP: Allow more content types
This commit is contained in:
parent
4238b9b3ef
commit
0cbdc852cb
1 changed files with 7 additions and 3 deletions
|
@ -18,9 +18,13 @@ module.exports = {
|
||||||
reportUri: '',
|
reportUri: '',
|
||||||
directives: {
|
directives: {
|
||||||
defaultSrc: ["'self'"],
|
defaultSrc: ["'self'"],
|
||||||
scriptSrc: ["'self'"],
|
scriptSrc: ["'self'", "'unsafe-eval'", "vimeo.com", "https://gist.github.com", "www.slideshare.net", "https://query.yahooapis.com", "https://*.disqus.com"],
|
||||||
styleSrc: ["'self'", "'unsafe-inline'"],
|
imgSrc: ["*"],
|
||||||
fontSrc: ["'self'"],
|
styleSrc: ["'self'", "'unsafe-inline'", "https://assets-cdn.github.com"],
|
||||||
|
fontSrc: ["'self'", "https://public.slidesharecdn.com"],
|
||||||
|
objectSrc: ["*"],
|
||||||
|
childSrc: ["*"],
|
||||||
|
connectSrc: ["'self'", "https://links.services.disqus.com", "wss://realtime.services.disqus.com"]
|
||||||
},
|
},
|
||||||
upgradeInsecureRequests: 'auto'
|
upgradeInsecureRequests: 'auto'
|
||||||
},
|
},
|
||||||
|
|
Loading…
Reference in a new issue