@@ -42,21 +42,27 @@ await app.register(helmet)
42
42
>
43
43
> ``` typescript
44
44
> await app .register (fastifyHelmet , {
45
- > contentSecurityPolicy: {
46
- > directives: {
47
- > defaultSrc: [` 'self' ` ],
48
- > styleSrc: [
49
- > ` 'self' ` ,
50
- > ` 'unsafe-inline' ` ,
51
- > ' cdn.jsdelivr.net' ,
52
- > ' fonts.googleapis.com' ,
53
- > ],
54
- > fontSrc: [` 'self' ` , ' fonts.gstatic.com' ],
55
- > imgSrc: [` 'self' ` , ' data:' , ' cdn.jsdelivr.net' ],
56
- > scriptSrc: [` 'self' ` , ` https: 'unsafe-inline' ` , ` cdn.jsdelivr.net ` ],
57
- > },
58
- > },
59
- > });
45
+ > contentSecurityPolicy: {
46
+ > directives: {
47
+ > defaultSrc: [` 'self' ` , ' unpkg.com' ],
48
+ > styleSrc: [
49
+ > ` 'self' ` ,
50
+ > ` 'unsafe-inline' ` ,
51
+ > ' cdn.jsdelivr.net' ,
52
+ > ' fonts.googleapis.com' ,
53
+ > ' unpkg.com' ,
54
+ > ],
55
+ > fontSrc: [` 'self' ` , ' fonts.gstatic.com' , ' data:' ],
56
+ > imgSrc: [` 'self' ` , ' data:' , ' cdn.jsdelivr.net' ],
57
+ > scriptSrc: [
58
+ > ` 'self' ` ,
59
+ > ` https: 'unsafe-inline' ` ,
60
+ > ` cdn.jsdelivr.net ` ,
61
+ > ` 'unsafe-eval' ` ,
62
+ > ],
63
+ > },
64
+ > },
65
+ > });
60
66
>
61
67
> // If you are not going to use CSP at all, you can use this:
62
68
> await app .register (fastifyHelmet , {
0 commit comments