Add to CSP
report-uri /csp-report; report-to csp-endpoint;">
This commit is contained in:
11
index.html
11
index.html
@@ -10,9 +10,16 @@
|
|||||||
font-src 'self' ;
|
font-src 'self' ;
|
||||||
connect-src 'self' https: ;
|
connect-src 'self' https: ;
|
||||||
img-src 'self' data:;
|
img-src 'self' data:;
|
||||||
media-src 'none';
|
font-src 'self';
|
||||||
|
manifest-src 'self';
|
||||||
|
worker-src 'self';
|
||||||
object-src 'none';
|
object-src 'none';
|
||||||
frame-src 'none';">
|
frame-ancestors 'none';
|
||||||
|
form-action 'self';
|
||||||
|
upgrade-insecure-requests;
|
||||||
|
block-all-mixed-content;
|
||||||
|
report-uri /csp-report;
|
||||||
|
report-to csp-endpoint;">
|
||||||
<meta http-equiv="X-Content-Type-Options" content="nosniff">
|
<meta http-equiv="X-Content-Type-Options" content="nosniff">
|
||||||
<meta http-equiv="X-XSS-Protection" content="1; mode=block">
|
<meta http-equiv="X-XSS-Protection" content="1; mode=block">
|
||||||
<meta http-equiv="Referrer-Policy" content="strict-origin-when-cross-origin">
|
<meta http-equiv="Referrer-Policy" content="strict-origin-when-cross-origin">
|
||||||
|
|||||||
Reference in New Issue
Block a user