From a85654437a1cd31bdcf5792d2ff6bbc5e153a7c7 Mon Sep 17 00:00:00 2001 From: Gusted Date: Tue, 27 Jul 2021 21:39:23 +0200 Subject: [PATCH] fix(handlers): correct CSP values --- handlers/core/CSP.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/handlers/core/CSP.go b/handlers/core/CSP.go index d2d07e32..902607a7 100644 --- a/handlers/core/CSP.go +++ b/handlers/core/CSP.go @@ -7,7 +7,7 @@ import ( var ( headerCSP = []byte(fiber.HeaderContentSecurityPolicy) - valueCSP = []byte("default-src 'none'; font-src https://fonts.imma.link; img-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests; base-uri: 'none'; object-src: 'none'; worker-src: 'none'; child-src: 'none'; frame-src: 'none';") + valueCSP = []byte("default-src 'none'; font-src https://fonts.imma.link; img-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests; base-uri 'none'; object-src 'none'; worker-src 'none'; child-src 'none'; frame-src 'none';") ) // CSPMiddleware adds the CSP Header