strongly segregate domains of main site and ugc in security policy

This commit is contained in:
byte[] 2021-03-16 20:24:58 -04:00
parent cc51981b05
commit 35e12420af

View file

@ -23,9 +23,9 @@ defmodule PhilomenaWeb.ContentSecurityPolicyPlug do
frame_src = Keyword.get(config, :frame_src, nil)
csp_config = [
{:default_src, ["'self'", cdn_uri]},
{:script_src, ["'self'", cdn_uri | script_src]},
{:style_src, ["'self'", cdn_uri | style_src]},
{:default_src, ["'self'"]},
{:script_src, ["'self'" | script_src]},
{:style_src, ["'self'" | style_src]},
{:object_src, ["'none'"]},
{:frame_ancestors, ["'none'"]},
{:frame_src, frame_src || ["'none'"]},