summaryrefslogtreecommitdiffstats
path: root/netlify.toml
diff options
context:
space:
mode:
authorSerghei Iakovlev <egrep@protonmail.ch>2022-07-02 22:02:24 +0200
committerSerghei Iakovlev <egrep@protonmail.ch>2022-07-02 22:02:24 +0200
commit03703ba1f49b1343b81d0635723efce9b566961a (patch)
tree51edddb0785b75f5f3557c7eb49e1b040c633ce3 /netlify.toml
parent70f63fa64222305054c82f9fc30f6d17a271a627 (diff)
downloadgohugo-theme-ed-03703ba1f49b1343b81d0635723efce9b566961a.tar.gz
Correct connect-src for CSP header
Diffstat (limited to 'netlify.toml')
-rw-r--r--netlify.toml2
1 files changed, 1 insertions, 1 deletions
diff --git a/netlify.toml b/netlify.toml
index 01b7af7..3149cec 100644
--- a/netlify.toml
+++ b/netlify.toml
@@ -68,7 +68,7 @@
# files received from those allowed domains, ignoring all other scripts
# (including inline scripts and event-handling HTML attributes).
#
- Content-Security-Policy = "default-src 'self'; script-src 'self' *.netlify.app *.netlify.com *.googletagmanager.com; style-src 'self'; img-src 'self' data: *.google-analytics.com *.googletagmanager.com; font-src 'self'; connect-src 'self' *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.doubleclick.net; media-src 'self'; object-src 'self'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self' submit-form.com; upgrade-insecure-requests; base-uri 'self'; manifest-src 'self'; report-uri https://egrep.report-uri.com/r/d/csp/enforce"
+ Content-Security-Policy = "default-src 'self'; script-src 'self' *.netlify.app *.netlify.com *.googletagmanager.com; style-src 'self'; img-src 'self' data: *.google-analytics.com *.googletagmanager.com; font-src 'self'; connect-src 'self' *.google-analytics.com analytics.google.com *.googletagmanager.com *.doubleclick.net; media-src 'self'; object-src 'self'; frame-src 'none'; worker-src 'self'; frame-ancestors 'none'; form-action 'self' submit-form.com; upgrade-insecure-requests; base-uri 'self'; manifest-src 'self'; report-uri https://egrep.report-uri.com/r/d/csp/enforce"
[[headers]]
for = '/feeds/*.xml'