Fixed builCsp.ts
This commit is contained in:
Vendored
+1
-1
@@ -14,7 +14,7 @@ export type BuildCspArgs = {
|
||||
/** YouTube embeds — adds youtube to frame-src. */
|
||||
youtube?: boolean;
|
||||
};
|
||||
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'object-src' | 'script-src' | 'style-src';
|
||||
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'media-src' | 'object-src' | 'script-src' | 'style-src' | 'worker-src';
|
||||
/**
|
||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||
* directives baked in, and opt-in sources for common third parties. Solves the
|
||||
|
||||
Vendored
+2
@@ -46,6 +46,7 @@
|
||||
'data:',
|
||||
'blob:'
|
||||
],
|
||||
'media-src': [],
|
||||
'script-src': [
|
||||
"'self'",
|
||||
"'unsafe-inline'"
|
||||
@@ -55,6 +56,7 @@
|
||||
"'unsafe-inline'",
|
||||
'https://fonts.googleapis.com'
|
||||
],
|
||||
'worker-src': [],
|
||||
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
||||
'base-uri': [
|
||||
"'self'"
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user