forked from colin/resume
2
0
Fork 0

Add form-action 'none' to CSP for additional security

This commit is contained in:
Your Name 2025-03-31 04:11:35 -04:00
parent 0b46750148
commit f739edc7eb
1 changed files with 1 additions and 1 deletions

View File

@ -26,7 +26,7 @@
Cross-Origin-Opener-Policy "same-origin"
# Simplified CSP for static content
Content-Security-Policy "default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self' data:; connect-src 'self'; object-src 'none'; frame-ancestors 'none'; require-sri-for script;"
Content-Security-Policy "default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self' data:; connect-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none'; require-sri-for script;"
}
# Handle 404s