Commit 8fd8c265 authored by Paul Colin Hennig's avatar Paul Colin Hennig
Browse files

fix csp for firefox

parent 627b392e
Pipeline #518 passed with stages
in 1 minute and 25 seconds
......@@ -4,7 +4,7 @@ add_header x-content-type-options nosniff;
add_header x-permitted-cross-domain-policies none;
add_header x-download-options noopen;
add_header x-xss-protection "1; mode=block";
add_header Content-Security-Policy "default-src 'none'; script-src 'self'; style-src 'self'; manifest-src 'self'; connect-src 'self'; media-src 'self'; img-src 'self'; font-src 'self'; worker-src 'self' blob:;child-src blob:;";
add_header Content-Security-Policy "default-src 'none'; script-src 'self'; style-src 'self'; manifest-src 'self'; connect-src 'self'; media-src 'self'; img-src 'self' blob:; font-src 'self'; worker-src 'self' blob:;child-src blob:;";
add_header Strict-Transport-Security "max-age=315360000; includeSubdomains; preload";
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment