Commit 4b2f287 1 parent 48e76cf commit 4b2f287 Copy full SHA for 4b2f287
File tree 2 files changed +13
-3
lines changed
2 files changed +13
-3
lines changed Original file line number Diff line number Diff line change @@ -14,6 +14,16 @@ module.exports = function(environment) {
14
14
APP : {
15
15
// Here you can pass flags/options to your application instance
16
16
// when it is created
17
+ } ,
18
+
19
+ contentSecurityPolicy : {
20
+ 'default-src' : "'none'" ,
21
+ 'script-src' : "'self' 'unsafe-eval'" ,
22
+ 'font-src' : "'self'" ,
23
+ 'connect-src' : "'self'" ,
24
+ 'img-src' : "'self'" ,
25
+ 'style-src' : "'self' 'unsafe-inline'" ,
26
+ 'media-src' : "'self'"
17
27
}
18
28
} ;
19
29
Original file line number Diff line number Diff line change 1
1
# Content Security Policy-Headers
2
2
# you have to enable apache module headers to get them working
3
- # Header set Content-Security-Policy "default-src 'self'"
4
- # Header set X-Content-Security-Policy "default-src 'self'"
5
- # Header set X-Webkit-CSP "default-src 'self'"
3
+ # Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; "
4
+ # Header set X-Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; "
5
+ # Header set X-Webkit-CSP "default-src 'self'; script-src 'self' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; "
You can’t perform that action at this time.
0 commit comments