fix: add turnstile in scriptsrc
This commit is contained in:
parent
960fc652b1
commit
b22d5f9f9a
@ -289,7 +289,7 @@ function createAppServerInitializer(context: ServiceInitializationContext): Serv
|
|||||||
},
|
},
|
||||||
cspDirectives: {
|
cspDirectives: {
|
||||||
defaultSrc: ["'self'"],
|
defaultSrc: ["'self'"],
|
||||||
scriptSrc: ["'self'", "'unsafe-inline'"],
|
scriptSrc: ["'self'", "'unsafe-inline'", "https://challenges.cloudflare.com"],
|
||||||
styleSrc: ["'self'", "'unsafe-inline'", staticCdnHost],
|
styleSrc: ["'self'", "'unsafe-inline'", staticCdnHost],
|
||||||
imgSrc: ["'self'", 'data:', 'blob:', publicUrlHost, mediaUrlHost, staticCdnHost],
|
imgSrc: ["'self'", 'data:', 'blob:', publicUrlHost, mediaUrlHost, staticCdnHost],
|
||||||
connectSrc: ["'self'", 'wss:', 'ws:', publicUrlHost],
|
connectSrc: ["'self'", 'wss:', 'ws:', publicUrlHost],
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user