Fixed builCsp.ts
This commit is contained in:
Vendored
+1
-1
@@ -14,7 +14,7 @@ export type BuildCspArgs = {
|
|||||||
/** YouTube embeds — adds youtube to frame-src. */
|
/** YouTube embeds — adds youtube to frame-src. */
|
||||||
youtube?: boolean;
|
youtube?: boolean;
|
||||||
};
|
};
|
||||||
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'object-src' | 'script-src' | 'style-src';
|
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'media-src' | 'object-src' | 'script-src' | 'style-src' | 'worker-src';
|
||||||
/**
|
/**
|
||||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||||
* directives baked in, and opt-in sources for common third parties. Solves the
|
* directives baked in, and opt-in sources for common third parties. Solves the
|
||||||
|
|||||||
Vendored
+2
@@ -46,6 +46,7 @@
|
|||||||
'data:',
|
'data:',
|
||||||
'blob:'
|
'blob:'
|
||||||
],
|
],
|
||||||
|
'media-src': [],
|
||||||
'script-src': [
|
'script-src': [
|
||||||
"'self'",
|
"'self'",
|
||||||
"'unsafe-inline'"
|
"'unsafe-inline'"
|
||||||
@@ -55,6 +56,7 @@
|
|||||||
"'unsafe-inline'",
|
"'unsafe-inline'",
|
||||||
'https://fonts.googleapis.com'
|
'https://fonts.googleapis.com'
|
||||||
],
|
],
|
||||||
|
'worker-src': [],
|
||||||
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
||||||
'base-uri': [
|
'base-uri': [
|
||||||
"'self'"
|
"'self'"
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
@@ -24,9 +24,11 @@ type CspDirective =
|
|||||||
| 'frame-ancestors'
|
| 'frame-ancestors'
|
||||||
| 'frame-src'
|
| 'frame-src'
|
||||||
| 'img-src'
|
| 'img-src'
|
||||||
|
| 'media-src'
|
||||||
| 'object-src'
|
| 'object-src'
|
||||||
| 'script-src'
|
| 'script-src'
|
||||||
| 'style-src'
|
| 'style-src'
|
||||||
|
| 'worker-src'
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||||
@@ -64,8 +66,10 @@ export function buildCsp(args: BuildCspArgs = {}): { key: string; value: string
|
|||||||
'form-action': ["'self'"],
|
'form-action': ["'self'"],
|
||||||
'frame-src': [],
|
'frame-src': [],
|
||||||
'img-src': ["'self'", 'data:', 'blob:'],
|
'img-src': ["'self'", 'data:', 'blob:'],
|
||||||
|
'media-src': [], // video/audio sources — filled via extra when needed
|
||||||
'script-src': ["'self'", "'unsafe-inline'"],
|
'script-src': ["'self'", "'unsafe-inline'"],
|
||||||
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
|
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
|
||||||
|
'worker-src': [], // web workers — filled via extra when needed
|
||||||
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
||||||
'base-uri': ["'self'"], // block <base> hijacking
|
'base-uri': ["'self'"], // block <base> hijacking
|
||||||
'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options)
|
'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options)
|
||||||
|
|||||||
Reference in New Issue
Block a user