We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent b2ea506 commit 95eef81Copy full SHA for 95eef81
frontend/nginx.conf
@@ -42,7 +42,7 @@ server {
42
}
43
44
location / {
45
- add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';";
+ add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'nonce-$request_id'; style-src 'self' 'nonce-$request_id'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none';";
46
add_header X-Frame-Options "SAMEORIGIN";
47
add_header X-Content-Type-Options "nosniff";
48
add_header Referrer-Policy "strict-origin-when-cross-origin";
0 commit comments