mirror of
https://github.com/dpnmw/community-landing.git
synced 2026-03-18 09:27:16 +00:00
Bug Fixes and UI Tweaks
This commit is contained in:
@@ -42,10 +42,12 @@ after_initialize do
|
||||
base_url = Discourse.base_url
|
||||
csp = "default-src 'self' #{base_url}; " \
|
||||
"script-src 'self' 'unsafe-inline'; " \
|
||||
"style-src 'self' 'unsafe-inline'; " \
|
||||
"style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; " \
|
||||
"style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; " \
|
||||
"img-src 'self' #{base_url} data: https:; " \
|
||||
"font-src 'self' #{base_url} https://fonts.gstatic.com; " \
|
||||
"media-src 'self' https:; " \
|
||||
"connect-src 'self' #{base_url}; " \
|
||||
"frame-src https://www.youtube.com https://www.youtube-nocookie.com; " \
|
||||
"frame-ancestors 'self'"
|
||||
response.headers["Content-Security-Policy"] = csp
|
||||
|
||||
Reference in New Issue
Block a user