fix(CSP): move trusted list to default-src

This commit is contained in:
Kalista Payne
2025-12-12 16:52:14 -06:00
parent 83b2ba7688
commit f51f0a0c93

View File

@@ -69,19 +69,17 @@ export default function attachMiddlewares (app, server) {
contentSecurityPolicy: { contentSecurityPolicy: {
directives: { directives: {
defaultSrc: [ defaultSrc: [
'*.habitica.com',
'*.amazonaws.com', '*.amazonaws.com',
],
imgSrc: null,
scriptSrc: [
'\'unsafe-eval\'',
'*.habitica.com', '*.habitica.com',
'*.amazonaws.com',
'cloudfront.loggly.com', 'cloudfront.loggly.com',
'js.stripe.com', 'js.stripe.com',
'm.stripe.network', 'm.stripe.network',
'static-na.payments-amazon.com', 'static-na.payments-amazon.com',
], ],
imgSrc: '*',
scriptSrc: [
'\'unsafe-eval\'',
],
upgradeInsecureRequests: IS_PROD ? [] : null, upgradeInsecureRequests: IS_PROD ? [] : null,
}, },
}, },