diff --git a/docker/resume/nginx.conf b/docker/resume/nginx.conf index 52b6f19..8e0f4af 100644 --- a/docker/resume/nginx.conf +++ b/docker/resume/nginx.conf @@ -9,7 +9,11 @@ server { add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), accelerometer=(), gyroscope=(), magnetometer=(), payment=(), usb=()" always; - add_header Content-Security-Policy "default-src 'none'; script-src 'self' https://matomo.nixc.us; style-src 'self' 'unsafe-inline' https://colinknapp.com; img-src 'self' https://matomo.nixc.us https://colinknapp.com; font-src 'self' data:; frame-ancestors 'self'; base-uri 'self'; form-action 'self';" always; + add_header Content-Security-Policy "default-src 'none'; script-src 'self' 'unsafe-inline' https://matomo.nixc.us; style-src 'self' 'unsafe-inline' https://colinknapp.com; img-src 'self' https://matomo.nixc.us https://colinknapp.com https://hedgedoc.nixc.us; font-src 'self' data:; frame-ancestors 'self'; base-uri 'self'; form-action 'self';" always; + + sub_filter "https://demo.hedgedoc.org" "https://hedgedoc.nixc.us"; + sub_filter_once off; + sub_filter_types text/html application/javascript; location / { try_files $uri $uri/ =404;