Fix CSP configuration to allow Bootstrap and external resources
ci/woodpecker/push/woodpecker Pipeline was successful
Details
ci/woodpecker/push/woodpecker Pipeline was successful
Details
This commit is contained in:
parent
d771718799
commit
6a2dd63ad3
|
@ -43,18 +43,23 @@ APP_ENV = os.environ.get('APP_ENV', 'development')
|
|||
# Configure security headers with Talisman
|
||||
# Base CSP settings
|
||||
csp = {
|
||||
'default-src': "'none'",
|
||||
'script-src': ["'self'",
|
||||
"'sha256-ryQsJ+aghKKD/CeXgx8jtsnZT3Epp3EjIw8RyHIq544='",
|
||||
"'sha256-anTkUs/oFZJulKUMaMjZlwaALEmPOP8op0psAo5Bhh8='",
|
||||
"'sha256-BASkmAmg7eoYCMd6odA6kQ8yGsFnoxaX48WbQvMkehs='"],
|
||||
'style-src': ["'self'", "'sha256-Mo+7o3oPEKpX7fqRvTtunvQHlIDhJ0SxAMG1PCNniCI='"],
|
||||
'img-src': ["'self'", "data:"],
|
||||
'font-src': ["'self'", "data:"],
|
||||
'default-src': ["'self'"],
|
||||
'script-src': [
|
||||
"'self'",
|
||||
"'unsafe-inline'",
|
||||
"https://cdn.jsdelivr.net/",
|
||||
],
|
||||
'style-src': [
|
||||
"'self'",
|
||||
"'unsafe-inline'",
|
||||
"https://cdn.jsdelivr.net/",
|
||||
],
|
||||
'img-src': ["'self'", "data:", "https:"],
|
||||
'font-src': ["'self'", "data:", "https://cdn.jsdelivr.net/"],
|
||||
'connect-src': "'self'",
|
||||
'object-src': "'none'",
|
||||
'frame-ancestors': "'none'",
|
||||
'base-uri': "'none'",
|
||||
'base-uri': "'self'",
|
||||
'form-action': "'self'"
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in New Issue