Skip to content

Commit 60795d6

Browse files
author
Ben Zörb
committed
fix(csp): adds videos.ctfassets.net to media-src & prefetch-src
1 parent 33c000b commit 60795d6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

templates/app/static/_headers

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,5 +5,5 @@
55
X-Content-Type-Options: nosniff
66
Strict-Transport-Security: max-age=2592000; includeSubDomains; preload
77
Feature-Policy: geolocation 'none'; midi 'none'; sync-xhr 'none'; microphone 'none'; camera 'none'; magnetometer 'none'; gyroscope 'none'; fullscreen 'none'; payment 'none'
8-
Content-Security-Policy: default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' https://images.ctfassets.net https://i.ytimg.com; font-src 'self'; connect-src 'self'; media-src 'self'; object-src 'none'; prefetch-src 'self' https://images.ctfassets.net; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com; worker-src 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'
8+
Content-Security-Policy: default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' https://images.ctfassets.net https://i.ytimg.com; font-src 'self'; connect-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; prefetch-src 'self' https://videos.ctfassets.net https://images.ctfassets.net; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com; worker-src 'self'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; manifest-src 'self'
99
Cache-Control: public, max-age=31536000

0 commit comments

Comments
 (0)