fix: update hero image and disable HSTS on localhost
This commit is contained in:
+5
-3
@@ -11,13 +11,13 @@ const cspHeader = `
|
||||
style-src 'self' 'unsafe-inline';
|
||||
img-src 'self' blob: data: https://images.unsplash.com https://placehold.co https://c.bing.com https://www.google-analytics.com;
|
||||
font-src 'self';
|
||||
connect-src 'self' https://www.google-analytics.com https://*.clarity.ms;
|
||||
connect-src 'self' ws: wss: https://www.google-analytics.com https://*.clarity.ms;
|
||||
frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/;
|
||||
object-src 'none';
|
||||
base-uri 'self';
|
||||
form-action 'self';
|
||||
frame-ancestors 'none';
|
||||
upgrade-insecure-requests;
|
||||
${process.env.NODE_ENV === 'production' ? 'upgrade-insecure-requests;' : ''}
|
||||
`.replace(/\s{2,}/g, ' ').trim();
|
||||
|
||||
const nextConfig: NextConfig = {
|
||||
@@ -41,8 +41,10 @@ const nextConfig: NextConfig = {
|
||||
{ key: 'X-XSS-Protection', value: '1; mode=block' },
|
||||
{ key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
|
||||
{ key: 'Content-Security-Policy', value: cspHeader },
|
||||
{ key: 'Strict-Transport-Security', value: 'max-age=31536000; includeSubDomains; preload' },
|
||||
{ key: 'Permissions-Policy', value: 'camera=(), microphone=(), geolocation=()' },
|
||||
...(process.env.NODE_ENV === 'production'
|
||||
? [{ key: 'Strict-Transport-Security', value: 'max-age=31536000; includeSubDomains; preload' }]
|
||||
: []),
|
||||
],
|
||||
},
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user