mirror of
https://github.com/PrivSec-dev/privsec.dev.git
synced 2025-04-20 07:26:01 -04:00
remove unsafe-inline from CSP
This commit is contained in:
parent
567dcf565d
commit
87c3fcf949
@ -2,7 +2,7 @@
|
||||
for = "/*"
|
||||
[headers.values]
|
||||
Strict-Transport-Security = "max-age=63072000; includeSubDomains; preload"
|
||||
Content-Security-Policy = "default-src 'self'; script-src 'self' 'unsafe-inline'; form-action 'none'; frame-ancestors 'none'; block-all-mixed-content; base-uri 'none'"
|
||||
Content-Security-Policy = "default-src 'self'; script-src 'self'; form-action 'none'; frame-ancestors 'none'; block-all-mixed-content; base-uri 'none'"
|
||||
X-Content-Type-Options = "nosniff"
|
||||
Referrer-Policy = "no-referrer"
|
||||
Cross-Origin-Opener-Policy = "same-origin"
|
||||
|
Loading…
x
Reference in New Issue
Block a user