summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSerghei Iakovlev <egrep@protonmail.ch>2022-06-02 02:06:26 +0200
committerSerghei Iakovlev <egrep@protonmail.ch>2022-06-02 02:06:26 +0200
commiteca807d667e0889fb0683aa955119677ad89532e (patch)
tree7dab22ecf78b0161eb5715de155328cc1a2fca12
parentf48478d45f9e8a00fa564de105f6c759231e28e9 (diff)
downloadgohugo-theme-ed-eca807d667e0889fb0683aa955119677ad89532e.tar.gz
Debug Content-Security-Policy header
-rw-r--r--netlify.toml3
1 files changed, 1 insertions, 2 deletions
diff --git a/netlify.toml b/netlify.toml
index 9eec95b..7e96b2d 100644
--- a/netlify.toml
+++ b/netlify.toml
@@ -77,8 +77,7 @@
# Allow forms to submit only to the current site and https://submit-form.com
#
# For more see: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
- # Content-Security-Policy = "default-src 'self'; img-src 'self' data:; object-src 'none'; script-src 'self';"
- Content-Security-Policy = "style-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self' 'https://submit-form.com';"
+ Content-Security-Policy = "default-src 'none'; base-uri 'self'; form-action 'self' 'https://submit-form.com'; img-src 'self' data:; script-src 'self'; style-src 'self'; font-src 'self'; worker-src 'self'; object-src 'self'; media-src 'self'; frame-ancestors 'none'; manifest-src 'self'; connect-src 'self'"
[[headers]]
for = '/feeds/*.xml'