forked from colin/resume
CORS?
This commit is contained in:
parent
1a8f06dc91
commit
701ed33198
|
@ -15,9 +15,18 @@ server {
|
|||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||||
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), accelerometer=(), gyroscope=(), magnetometer=(), payment=(), usb=()" always;
|
||||
|
||||
# Content Security Policy (CSP) with injected $nonce for script-src and style-src
|
||||
# Allows inline scripts and styles that match the nonce generated for each request
|
||||
add_header Content-Security-Policy "default-src 'none'; script-src 'self' 'nonce-$nonce' https://matomo.nixc.us; style-src 'self' 'nonce-$nonce' https://colinknapp.com; img-src 'self' https://matomo.nixc.us https://colinknapp.com https://hedgedoc.nixc.us; font-src 'self' data:; frame-ancestors 'self'; base-uri 'self'; form-action 'self';" always;
|
||||
# Updated Content Security Policy (CSP) with specified external domains
|
||||
add_header Content-Security-Policy "
|
||||
default-src 'none';
|
||||
script-src 'self' 'nonce-$nonce' https://matomo.nixc.us https://gist.github.com https://assets-cdn.github.com;
|
||||
style-src 'self' 'nonce-$nonce' https://colinknapp.com https://getbootstrap.com https://fonts.googleapis.com;
|
||||
img-src 'self' https://matomo.nixc.us https://colinknapp.com https://hedgedoc.nixc.us https://assets-cdn.github.com https://github.com https://forkaweso.me https://ionicons.com https://twitter.com data:;
|
||||
font-src 'self' https://fonts.gstatic.com https://github.com https://forkaweso.me;
|
||||
connect-src 'self' https://matomo.nixc.us;
|
||||
frame-ancestors 'self';
|
||||
base-uri 'self';
|
||||
form-action 'self';
|
||||
" always;
|
||||
|
||||
# Cross-origin isolation headers
|
||||
add_header Cross-Origin-Embedder-Policy "require-corp" always;
|
||||
|
|
Loading…
Reference in New Issue