Optimized CSP policies

This commit is contained in:
Kevin Veen-Birkenbach 2025-05-15 15:11:55 +02:00
parent be0da93c9c
commit fd698e9cc6
No known key found for this signature in database
GPG Key ID: 44D8F11FD62F878E
2 changed files with 9 additions and 4 deletions

View File

@ -20,12 +20,13 @@ csp:
flags: flags:
script-src: script-src:
unsafe-inline: true unsafe-inline: true
unsafe-eval: true
style-src: style-src:
unsafe-inline: true unsafe-inline: true
whitelist: whitelist:
connect-src: connect-src:
- "{{ domains.element }}" - "{{ primary_domain }}"
- "{{ domains.synapse }}" - "{{ domains.synapse }}"
script-src: script-src:
- "{{ domains.element }}"
- "{{ domains.synapse }}" - "{{ domains.synapse }}"
- "https://cdn.jsdelivr.net"

View File

@ -30,4 +30,8 @@ csp:
- "data:" - "data:"
script-src: script-src:
- "https://cdn.gtranslate.net" - "https://cdn.gtranslate.net"
- "{{ domains.wordpress }}" - "{{ domains.wordpress[0] }}"
frame-src:
- "{{ domains.peertube }}"
style-src:
- "https://fonts.bunny.net"