Fix content security policy (why?)
This commit is contained in:
parent
b1a7e04158
commit
da2759c055
|
@ -7,7 +7,10 @@ export default [
|
||||||
contentSecurityPolicy: {
|
contentSecurityPolicy: {
|
||||||
useDefaults: true,
|
useDefaults: true,
|
||||||
directives: {
|
directives: {
|
||||||
'connect-src': ["'self'", 'http:', 'https:'],
|
'connect-src': ["'self'", 'https:'],
|
||||||
|
'script-src': ["'self'", "'unsafe-inline'", 'api.enderman.ch', 'cdn.jsdelivr.net'],
|
||||||
|
'img-src': ["'self'", 'data:', 'blob:', 'api.enderman.ch', 'cdn.jsdelivr.net', 'strapi.io'],
|
||||||
|
'media-src': ["'self'", 'data:', 'blob:', 'api.enderman.ch'],
|
||||||
upgradeInsecureRequests: null,
|
upgradeInsecureRequests: null,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|
Loading…
Reference in New Issue