Skip to content

Commit

Permalink
Add swagger validator to allowed external images
Browse files Browse the repository at this point in the history
  • Loading branch information
axelstudios committed Aug 6, 2020
1 parent 5f338bd commit 7f80d1a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docker/nginx-seed.conf
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ add_header X-XSS-Protection "1; mode=block";
# https://www.html5rocks.com/en/tutorials/security/content-security-policy/
# https://www.owasp.org/index.php/Content_Security_Policy
# https://www.html5rocks.com/en/tutorials/security/content-security-policy/#inline-code-considered-harmful
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https://stamen-tiles-a.a.ssl.fastly.net https://stamen-tiles-b.a.ssl.fastly.net https://stamen-tiles-c.a.ssl.fastly.net https://stamen-tiles-d.a.ssl.fastly.net; style-src 'self' 'unsafe-inline'; frame-src 'self'; object-src 'none'";
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https://stamen-tiles-a.a.ssl.fastly.net https://stamen-tiles-b.a.ssl.fastly.net https://stamen-tiles-c.a.ssl.fastly.net https://stamen-tiles-d.a.ssl.fastly.net https://validator.swagger.io; style-src 'self' 'unsafe-inline'; frame-src 'self'; object-src 'none'";

# HSTS
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
Expand Down

0 comments on commit 7f80d1a

Please sign in to comment.