mirror of
https://github.com/philomena-dev/philomena.git
synced 2024-11-23 20:18:00 +01:00
strongly segregate domains of main site and ugc in security policy
This commit is contained in:
parent
cc51981b05
commit
35e12420af
1 changed files with 3 additions and 3 deletions
|
@ -23,9 +23,9 @@ defmodule PhilomenaWeb.ContentSecurityPolicyPlug do
|
|||
frame_src = Keyword.get(config, :frame_src, nil)
|
||||
|
||||
csp_config = [
|
||||
{:default_src, ["'self'", cdn_uri]},
|
||||
{:script_src, ["'self'", cdn_uri | script_src]},
|
||||
{:style_src, ["'self'", cdn_uri | style_src]},
|
||||
{:default_src, ["'self'"]},
|
||||
{:script_src, ["'self'" | script_src]},
|
||||
{:style_src, ["'self'" | style_src]},
|
||||
{:object_src, ["'none'"]},
|
||||
{:frame_ancestors, ["'none'"]},
|
||||
{:frame_src, frame_src || ["'none'"]},
|
||||
|
|
Loading…
Reference in a new issue