From a9e16c890f57e465b4a45efd66443794f2223b1b Mon Sep 17 00:00:00 2001 From: Christian Winther Date: Wed, 15 May 2024 13:54:46 +0200 Subject: [PATCH] fix(docs): fix CSP rules --- netlify.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/netlify.toml b/netlify.toml index 6d6457fb82..d19fe178dc 100644 --- a/netlify.toml +++ b/netlify.toml @@ -21,7 +21,7 @@ [headers.values] X-Frame-Options = "DENY" X-XSS-Protection = "1; mode=block" - Content-Security-Policy = "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:" + Content-Security-Policy = "default-src 'self'; frame-src 'self' https://app.netlify.com; script-src 'self' https://*.google-analytics.com https://www.googletagmanager.com https://*.algolianet.com https://*.algolia.net 'unsafe-inline'; style-src 'self' https://fonts.googleapis.com https://*.algolianet.com https://*.algolia.net 'unsafe-inline'; img-src 'self' https://*.google-analytics.com data:; font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com; connect-src 'self' https://*.google-analytics.com https://www.googletagmanager.com https://*.algolianet.com https://*.algolia.net" Cache-Control = "public, max-age=86400, must-revalidate" Strict-Transport-Security = "max-age=86400; includeSubDomains; preload" Referrer-Policy = "no-referrer"