Skip to content

Commit

Permalink
fix: 🐛 csp
Browse files Browse the repository at this point in the history
added preview env
  • Loading branch information
StanGirard committed Jan 14, 2024
1 parent 35aa95e commit b21e754
Showing 1 changed file with 15 additions and 6 deletions.
21 changes: 15 additions & 6 deletions frontend/next.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ const ContentSecurityPolicy = {
process.env.NEXT_PUBLIC_SUPABASE_URL,
"https://api.june.so",
"https://us.posthog.com",
"https://preview.quivr.app",
"https://*-quivr-app.vercel.app/",
process.env.NEXT_PUBLIC_FRONTEND_URL,
],
"connect-src": [
Expand All @@ -48,7 +50,7 @@ const ContentSecurityPolicy = {
"https://api.openai.com",
"https://cdn.growthbook.io",
"https://vitals.vercel-insights.com/v1/vitals",
"https://us.posthog.com"
"https://us.posthog.com",
],
"img-src": [
"'self'",
Expand All @@ -62,21 +64,28 @@ const ContentSecurityPolicy = {
"https://user-images.githubusercontent.com",
process.env.NEXT_PUBLIC_FRONTEND_URL,
"https://quivr-cms.s3.eu-west-3.amazonaws.com",
"https://preview.quivr.app",
"https://*-quivr-app.vercel.app/",
],
"script-src": [
"'unsafe-inline'",
"'unsafe-eval'",
"https://va.vercel-scripts.com/",
process.env.NEXT_PUBLIC_FRONTEND_URL,
"https://preview.quivr.app",
"https://*-quivr-app.vercel.app/",
"https://www.google-analytics.com/",
"https://js.stripe.com",
"https://us.posthog.com"
],
"frame-src": ["https://js.stripe.com",
"https://us.posthog.com"
"https://us.posthog.com",
],
"frame-src": ["https://js.stripe.com", "https://us.posthog.com"],
"frame-ancestors": ["'none'"],
"style-src": ["'unsafe-inline'", process.env.NEXT_PUBLIC_FRONTEND_URL],
"style-src": [
"'unsafe-inline'",
process.env.NEXT_PUBLIC_FRONTEND_URL,
"https://preview.quivr.app",
"https://*-quivr-app.vercel.app/",
],
};

// Build CSP string
Expand Down

0 comments on commit b21e754

Please sign in to comment.