From cb9dd8c26d7708e409301747a5752e5e23b3a833 Mon Sep 17 00:00:00 2001 From: Hoang Nguyen Date: Fri, 29 Dec 2023 00:00:00 +0700 Subject: [PATCH] Add more Content-Security-Policy values Can be checked on https://csp-evaluator.withgoogle.com/ --- src/_headers | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/_headers b/src/_headers index 77130df..a4166b0 100644 --- a/src/_headers +++ b/src/_headers @@ -4,4 +4,4 @@ X-DNS-Prefetch-Control: off Referrer-Policy: no-referrer Permissions-Policy: interest-cohort=(), geolocation=(), camera=(), microphone=(), display-capture=(), web-share=() - Content-Security-Policy: default-src 'self'; script-src 'none'; frame-ancestors 'none'; child-src 'none'; base-uri 'self' + Content-Security-Policy: default-src 'self'; script-src 'none'; frame-ancestors 'none'; child-src 'none'; base-uri 'self'; object-src 'none'; require-trusted-types-for 'script'