Skip to content

Commit c5e8070

Browse files
committed
unsafe-inline 2
1 parent 491f9be commit c5e8070

File tree

3 files changed

+5
-2
lines changed

3 files changed

+5
-2
lines changed

Gemfile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,5 @@ source "https://rubygems.org"
22

33
gem "rspec"
44
gem "rake"
5+
gem 'openssl'
56

Gemfile.lock

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ GEM
22
remote: https://rubygems.org/
33
specs:
44
diff-lcs (1.6.2)
5+
openssl (3.3.2)
56
rake (13.3.1)
67
rspec (3.13.2)
78
rspec-core (~> 3.13.0)
@@ -21,6 +22,7 @@ PLATFORMS
2122
ruby
2223

2324
DEPENDENCIES
25+
openssl
2426
rake
2527
rspec
2628

config/nginx.conf.erb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -503,7 +503,7 @@ http {
503503
set $csp_policy "";
504504
set $csp_policy_report "";
505505
if ($http_x_forwarded_proto = "https") {
506-
set $csp_policy "upgrade-insecure-requests; frame-ancestors 'none'; script-src 'unsafe-inline'; script-src 'unsafe-eval'; style-src 'unsafe-inline'; default-src https:";
506+
set $csp_policy "frame-ancestors 'none'; script-src 'unsafe-inline'; script-src 'unsafe-eval'; style-src 'unsafe-inline'; default-src https:";
507507
set $csp_policy_report "default-src https:; script-src 'unsafe-inline'; report-uri https://<%= primary_host %>/_csp";
508508
}
509509
add_header X-Content-Type-Options "nosniff";
@@ -517,7 +517,7 @@ http {
517517
proxy_hide_header Cache-Control;
518518
proxy_hide_header Expires;
519519
# 2015 sites and prior had mixed content issues
520-
set $csp_policy "upgrade-insecure-requests; frame-ancestors 'none'; default-src https:";
520+
set $csp_policy "upgrade-insecure-requests; frame-ancestors 'none'; script-src 'unsafe-inline'; script-src 'unsafe-eval'; style-src 'unsafe-inline'; default-src https:";
521521
add_header Cache-Control "public, max-age=604800, s-maxage=31536000";
522522
proxy_pass https://2009-2011.rubykaigi.org;
523523
}

0 commit comments

Comments
 (0)