Skip to content

Commit ec81cd6

Browse files
committed
Merge branch 'dev' of https://github.com/umami-software/umami into dev
2 parents 1809959 + cd6ad0a commit ec81cd6

File tree

1 file changed

+9
-12
lines changed

1 file changed

+9
-12
lines changed

next.config.ts

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -14,14 +14,14 @@ const frameAncestors = process.env.ALLOWED_FRAME_URLS || '';
1414
const trackerScriptName = process.env.TRACKER_SCRIPT_NAME || '';
1515
const trackerScriptURL = process.env.TRACKER_SCRIPT_URL || '';
1616

17-
const contentSecurityPolicy = [
18-
`default-src 'self'`,
19-
`img-src * data:`,
20-
`script-src 'self' 'unsafe-eval' 'unsafe-inline'`,
21-
`style-src 'self' 'unsafe-inline'`,
22-
`connect-src 'self' api.umami.is cloud.umami.is`,
23-
`frame-ancestors 'self' ${frameAncestors}`,
24-
];
17+
const contentSecurityPolicy = `
18+
default-src 'self';
19+
img-src 'self' https: data:;
20+
script-src 'self' 'unsafe-eval' 'unsafe-inline';
21+
style-src 'self' 'unsafe-inline';
22+
connect-src *;
23+
frame-ancestors 'self' ${frameAncestors};
24+
`;
2525

2626
const defaultHeaders = [
2727
{
@@ -30,10 +30,7 @@ const defaultHeaders = [
3030
},
3131
{
3232
key: 'Content-Security-Policy',
33-
value: contentSecurityPolicy
34-
.join(';')
35-
.replace(/\s{2,}/g, ' ')
36-
.trim(),
33+
value: contentSecurityPolicy.replace(/\s{2,}/g, ' ').trim(),
3734
},
3835
];
3936

0 commit comments

Comments
 (0)