Skip to content

Commit 65c2e26

Browse files
committed
remove deprecated widget
1 parent f1b7db3 commit 65c2e26

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

guides/csp-configuration.mdx

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,6 @@ The following CSP directives are used to control which resources can be loaded:
2525
| `d4tuoctqmanu0.cloudfront.net` | KaTeX CSS, fonts | `style-src`, `font-src` | Required |
2626
| `*.mintlify.dev` | Documentation content | `connect-src` | Required |
2727
| `d3gk2c5xim1je2.cloudfront.net` | Icons, images, logos | `img-src` | Required |
28-
| `unpkg.com` | Mintlify widget scripts | `script-src` | Required |
2928
| `www.googletagmanager.com` | Google Analytics/GTM | `script-src`, `connect-src` | Optional |
3029
| `cdn.segment.com` | Segment analytics | `script-src`, `connect-src` | Optional |
3130
| `plausible.io` | Plausible analytics | `script-src`, `connect-src` | Optional |
@@ -43,7 +42,7 @@ The following CSP directives are used to control which resources can be loaded:
4342
```text wrap
4443
Content-Security-Policy:
4544
default-src 'self';
46-
script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com www.googletagmanager.com cdn.segment.com plausible.io tag.clearbitscripts.com cdn.heapanalytics.com
45+
script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com cdn.segment.com plausible.io tag.clearbitscripts.com cdn.heapanalytics.com
4746
chat.cdn-plain.com chat-assets.frontapp.com;
4847
style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net;
4948
font-src 'self' d4tuoctqmanu0.cloudfront.net;
@@ -67,7 +66,7 @@ Create a Response Header Transform Rule:
6766
- **Header name**: `Content-Security-Policy`
6867
- **Header value**:
6968
```text wrap
70-
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;
69+
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;
7170
```
7271
4. Deploy your rule.
7372

@@ -82,7 +81,7 @@ Add a response headers policy in CloudFront:
8281
"Config": {
8382
"SecurityHeadersConfig": {
8483
"ContentSecurityPolicy": {
85-
"ContentSecurityPolicy": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;",
84+
"ContentSecurityPolicy": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;",
8685
"Override": true
8786
}
8887
}
@@ -103,7 +102,7 @@ Add to your `vercel.json`:
103102
"headers": [
104103
{
105104
"key": "Content-Security-Policy",
106-
"value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;"
105+
"value": "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;"
107106
}
108107
]
109108
}

0 commit comments

Comments
 (0)