summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSerghei Iakovlev <egrep@protonmail.ch>2022-07-04 10:50:58 +0200
committerSerghei Iakovlev <egrep@protonmail.ch>2022-07-04 10:50:58 +0200
commit7d836dd207ab23c66eaa246b35ed98fce62859ea (patch)
treeafac46387e520b626668acc3ce9df6288a17ef50
parent2d3877158eed52de104ebe3e57db3874e7d981b1 (diff)
downloadgohugo-theme-ed-7d836dd207ab23c66eaa246b35ed98fce62859ea.tar.gz
Add gstatic.com to allowed hosts for CSP header
-rw-r--r--netlify.toml2
1 files changed, 1 insertions, 1 deletions
diff --git a/netlify.toml b/netlify.toml
index a1dbd9f..ff4a1e7 100644
--- a/netlify.toml
+++ b/netlify.toml
@@ -68,7 +68,7 @@
# files received from those allowed domains, ignoring all other scripts
# (including inline scripts and event-handling HTML attributes).
#
- Content-Security-Policy = "default-src 'self'; script-src 'self' *.netlify.app *.netlify.com *.googletagmanager.com; style-src 'self'; img-src 'self' data: *.google-analytics.com *.googletagmanager.com; font-src 'self'; connect-src 'self' *.google-analytics.com analytics.google.com *.googletagmanager.com *.doubleclick.net; media-src 'self'; object-src 'self'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self' submit-form.com; upgrade-insecure-requests; base-uri 'self'; manifest-src 'self'; report-uri https://egrep.report-uri.com/r/d/csp/enforce"
+ Content-Security-Policy = "default-src 'self'; script-src 'self' *.netlify.app *.netlify.com *.googletagmanager.com; style-src 'self'; img-src 'self' data: *.google-analytics.com *.googletagmanager.com *.gstatic.com; font-src 'self'; connect-src 'self' *.google-analytics.com analytics.google.com *.googletagmanager.com *.doubleclick.net; media-src 'self'; object-src 'self'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self' submit-form.com; upgrade-insecure-requests; base-uri 'self'; manifest-src 'self'; report-uri https://egrep.report-uri.com/r/d/csp/enforce"
[[headers]]
for = '/feeds/*.xml'