@@ -25,7 +25,6 @@ The following CSP directives are used to control which resources can be loaded:
2525|  ` d4tuoctqmanu0.cloudfront.net `  |  KaTeX CSS, fonts |  ` style-src ` , ` font-src `  |  Required | 
2626|  ` *.mintlify.dev `  |  Documentation content |  ` connect-src `  |  Required | 
2727|  ` d3gk2c5xim1je2.cloudfront.net `  |  Icons, images, logos |  ` img-src `  |  Required | 
28- |  ` unpkg.com `  |  Mintlify widget scripts |  ` script-src `  |  Required | 
2928|  ` www.googletagmanager.com `  |  Google Analytics/GTM |  ` script-src ` , ` connect-src `  |  Optional | 
3029|  ` cdn.segment.com `  |  Segment analytics |  ` script-src ` , ` connect-src `  |  Optional | 
3130|  ` plausible.io `  |  Plausible analytics |  ` script-src ` , ` connect-src `  |  Optional | 
@@ -43,7 +42,7 @@ The following CSP directives are used to control which resources can be loaded:
4342``` text  wrap
4443Content-Security-Policy: 
4544default-src 'self'; 
46- script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com  www.googletagmanager.com cdn.segment.com plausible.io tag.clearbitscripts.com cdn.heapanalytics.com 
45+ script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com cdn.segment.com plausible.io tag.clearbitscripts.com cdn.heapanalytics.com 
4746chat.cdn-plain.com chat-assets.frontapp.com; 
4847style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; 
4948font-src 'self' d4tuoctqmanu0.cloudfront.net; 
@@ -67,7 +66,7 @@ Create a Response Header Transform Rule:
6766  -  ** Header name** : ` Content-Security-Policy ` 
6867  -  ** Header value** :
6968    ``` text  wrap
70-     default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com ; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev; 
69+     default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev; 
7170``` 
72714 .  Deploy your rule.
7372
@@ -82,7 +81,7 @@ Add a response headers policy in CloudFront:
8281    "Config" : {
8382    "SecurityHeadersConfig" : {
8483        "ContentSecurityPolicy" : {
85-         "ContentSecurityPolicy" : " default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com ; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;" 
84+         "ContentSecurityPolicy" : " default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;" 
8685        "Override" : true 
8786        }
8887      }
@@ -103,7 +102,7 @@ Add to your `vercel.json`:
103102    "headers" : [
104103        {
105104        "key" : " Content-Security-Policy" 
106-         "value" : " default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com ; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;" 
105+         "value" : " default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' d4tuoctqmanu0.cloudfront.net; font-src 'self' d4tuoctqmanu0.cloudfront.net; img-src 'self' data: blob: d3gk2c5xim1je2.cloudfront.net; connect-src 'self' *.mintlify.dev; frame-src 'self' *.mintlify.dev;" 
107106        }
108107      ]
109108    }
0 commit comments