Skip to content

Commit

Permalink
csp fix
Browse files Browse the repository at this point in the history
  • Loading branch information
jekuer committed Sep 29, 2023
1 parent ee9b2fa commit 2137575
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 13 deletions.
13 changes: 1 addition & 12 deletions demo/nuxt.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -43,19 +43,8 @@ export default defineNuxtConfig({
crossOriginResourcePolicy: 'cross-origin',
crossOriginOpenerPolicy: 'same-origin',
crossOriginEmbedderPolicy: 'unsafe-none',
contentSecurityPolicy: false,
// the following needs to match the settings in ./public/staticwebapp.config.json
contentSecurityPolicy: {
'base-uri': ["'self'"],
'font-src': ["'self' data:"],
'form-action': ["'self'"],
'frame-ancestors': ["'self'"],
'img-src': ["'self' https://add-to-calendar-button.com data:"],
'object-src': ["'none'"],
'script-src-attr': ["'self'"],
'script-src': ["'self' 'unsafe-inline' https://*.add-to-calendar-button.com"],
'style-src': ["'self' 'unsafe-inline' https://add-to-calendar-button.com"],
'upgrade-insecure-requests': true,
},
referrerPolicy: 'strict-origin-when-cross-origin',
strictTransportSecurity: {
maxAge: 31536000,
Expand Down
2 changes: 1 addition & 1 deletion demo/public/staticwebapp.config.json
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
"Referrer-Policy": "strict-origin-when-cross-origin",
"Access-Control-Allow-Methods": "GET",
"Content-Security-Policy": "base-uri 'self'; font-src 'self' data:; form-action 'self'; frame-ancestors 'self'; img-src 'self' https://add-to-calendar-button.com data:; object-src 'none'; script-src-attr 'self'; script-src 'self' 'unsafe-inline' https://*.add-to-calendar-button.com; style-src 'self' 'unsafe-inline' https://add-to-calendar-button.com;",
"Content-Security-Policy": "base-uri 'self'; font-src 'self' data:; form-action 'self'; frame-ancestors 'self'; img-src 'self' https://add-to-calendar-button.com data:; object-src 'none'; script-src-attr 'self'; script-src 'self' 'unsafe-inline' https://*.add-to-calendar-button.com; style-src 'self' 'unsafe-inline' https://add-to-calendar-button.com; ; upgrade-insecure-requests;",
"Permissions-Policy": "geolocation=(),midi=(),microphone=(),camera=(),gyroscope=(*),encrypted-media=(*),payment=()"
}
}

0 comments on commit 2137575

Please sign in to comment.