From 237f6eafc000707ae1745486adcb8b76598e8cd9 Mon Sep 17 00:00:00 2001 From: Tommy Date: Sun, 23 Jun 2024 12:53:19 -0700 Subject: [PATCH] Rearrange CSP policies Signed-off-by: Tommy --- static/_headers | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/static/_headers b/static/_headers index 42928ad..6a1b0a3 100644 --- a/static/_headers +++ b/static/_headers @@ -1,6 +1,6 @@ /* Strict-Transport-Security : max-age=63072000; includeSubDomains; preload - Content-Security-Policy : default-src 'none'; connect-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; form-action 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'none' + Content-Security-Policy : default-src 'none'; connect-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; base-uri 'none'; block-all-mixed-content; form-action 'none'; frame-ancestors 'none'; upgrade-insecure-requests X-Content-Type-Options : nosniff Referrer-Policy : no-referrer X-Frame-Options : DENY