Skip to content

Commit 9daaac3

Browse files
Merge pull request #33 from DataKitchen/release/2.7.5
Release/2.7.5
2 parents 2fe1270 + e34d051 commit 9daaac3

File tree

2 files changed

+9
-2
lines changed

2 files changed

+9
-2
lines changed

observability_ui/apps/shell/src/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
<link href="https://fonts.googleapis.com/icon?family=Material+Icons" rel="stylesheet">
1515

1616
<link rel="preload"
17-
href="https://cdn.materialdesignicons.com/6.5.95/css/materialdesignicons.min.css"
17+
href="https://cdn.jsdelivr.net/npm/@mdi/font@6.5.95/css/materialdesignicons.min.css"
1818
as="style"
1919
integrity="sha512-Zw6ER2h5+Zjtrej6afEKgS8G5kehmDAHYp9M2xf38MPmpUWX39VrYmdGtCrDQbdLQrTnBVT8/gcNhgS4XPgvEg=="
2020
crossorigin="anonymous"

observability_ui/nginx.conf

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,14 @@ http {
6565
try_files /shell$uri /shell/index.html =404;
6666

6767
add_header X-Content-Type-Options nosniff always;
68-
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'nonce-${request_id}' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.materialdesignicons.com https://cdn.jsdelivr.net; img-src 'self' data:; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net; frame-ancestors 'none'; connect-src 'self' https://fonts.gstatic.com https://cdn.materialdesignicons.com https://cdn.jsdelivr.net ${api_hostname}; ${csp_extra}" always;
68+
add_header X-Frame-Options deny always;
69+
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
70+
add_header Referrer-Policy strict-origin-when-cross-origin;
71+
add_header Permissions-Policy "attribution-reporting=(self),deferred-fetch=(self),deferred-fetch-minimal=(self),fullscreen=(self),storage-access=(self),web-share=(self),accelerometer=(),autoplay=(),bluetooth=(),camera=(),captured-surface-control=(),compute-pressure=(),cross-origin-isolated=(),display-capture=(),encrypted-media=(),gamepad=(),geolocation=(),gyroscope=(),hid=(),identity-credentials-get=(),idle-detection=(),language-detector=(),microphone=(),local-fonts=(),midi=(),otp-credentials=(),payment=(),picture-in-picture=(),publickey-credentials-create=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),summarizer=(),translator=(),usb=(),window-management=(),xr-spatial-tracking=()";
72+
add_header Cross-Origin-Opener-Policy same-origin;
73+
add_header Cross-Origin-Resource-Policy same-origin;
74+
add_header Cross-Origin-Embedder-Policy require-corp;
75+
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'nonce-${request_id}' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src 'self' data:; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net; frame-ancestors 'none'; connect-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net ${api_hostname}; ${csp_extra}" always;
6976
}
7077
}
7178
}

0 commit comments

Comments
 (0)