Fixed builCsp.ts
This commit is contained in:
@@ -24,9 +24,11 @@ type CspDirective =
|
||||
| 'frame-ancestors'
|
||||
| 'frame-src'
|
||||
| 'img-src'
|
||||
| 'media-src'
|
||||
| 'object-src'
|
||||
| 'script-src'
|
||||
| 'style-src'
|
||||
| 'worker-src'
|
||||
|
||||
/**
|
||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||
@@ -64,8 +66,10 @@ export function buildCsp(args: BuildCspArgs = {}): { key: string; value: string
|
||||
'form-action': ["'self'"],
|
||||
'frame-src': [],
|
||||
'img-src': ["'self'", 'data:', 'blob:'],
|
||||
'media-src': [], // video/audio sources — filled via extra when needed
|
||||
'script-src': ["'self'", "'unsafe-inline'"],
|
||||
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
|
||||
'worker-src': [], // web workers — filled via extra when needed
|
||||
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
||||
'base-uri': ["'self'"], // block <base> hijacking
|
||||
'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options)
|
||||
|
||||
Reference in New Issue
Block a user