Skip to content

Commit 50cb227

Browse files
authored
Fix CSP error (#60)
* add netlify domain to frame-src * add domain to default src * add netlify to script src * fix script src * add blob * allow camera and microphone * format header file * update comments * keep csp only * revert format * netlify.app * add cross domain
1 parent 6e303fa commit 50cb227

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

src/_headers

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,9 @@
11
/*
2-
X-Frame-Options: DENY
3-
X-XSS-Protection: 1; mode=block
2+
X-Frame-Options: SAMEORIGIN
43
X-Content-Type-Options: nosniff
54
Referrer-Policy: strict-origin-when-cross-origin
6-
Permissions-Policy: accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
7-
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https://api.github.com/
5+
Cross-Origin-Resource-Policy: cross-origin
6+
Cross-Origin-Embedder-Policy: require-corp
7+
Cross-Origin-Opener-Policy: same-origin
8+
Permissions-Policy: accelerometer=(), camera=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(self), payment=(), usb=()
9+
Content-Security-Policy: default-src 'self' https://*.netlify.com https://*.netlify.app; script-src 'self' blob: https://*.netlify.com https://*.netlify.app 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https://api.github.com/

0 commit comments

Comments
 (0)