mirror of
https://github.com/HabitRPG/habitica.git
synced 2025-12-14 05:07:22 +01:00
fix(CSP): move trusted list to default-src
This commit is contained in:
@@ -69,19 +69,17 @@ export default function attachMiddlewares (app, server) {
|
|||||||
contentSecurityPolicy: {
|
contentSecurityPolicy: {
|
||||||
directives: {
|
directives: {
|
||||||
defaultSrc: [
|
defaultSrc: [
|
||||||
'*.habitica.com',
|
|
||||||
'*.amazonaws.com',
|
'*.amazonaws.com',
|
||||||
],
|
|
||||||
imgSrc: null,
|
|
||||||
scriptSrc: [
|
|
||||||
'\'unsafe-eval\'',
|
|
||||||
'*.habitica.com',
|
'*.habitica.com',
|
||||||
'*.amazonaws.com',
|
|
||||||
'cloudfront.loggly.com',
|
'cloudfront.loggly.com',
|
||||||
'js.stripe.com',
|
'js.stripe.com',
|
||||||
'm.stripe.network',
|
'm.stripe.network',
|
||||||
'static-na.payments-amazon.com',
|
'static-na.payments-amazon.com',
|
||||||
],
|
],
|
||||||
|
imgSrc: '*',
|
||||||
|
scriptSrc: [
|
||||||
|
'\'unsafe-eval\'',
|
||||||
|
],
|
||||||
upgradeInsecureRequests: IS_PROD ? [] : null,
|
upgradeInsecureRequests: IS_PROD ? [] : null,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user