[FIX] Fix some securiry issues
This commit is contained in:
@@ -14,6 +14,21 @@ const config = {
|
||||
}),
|
||||
alias: {
|
||||
$lib: './src/lib'
|
||||
},
|
||||
// Security: Content Security Policy
|
||||
csp: {
|
||||
directives: {
|
||||
'default-src': ['self'],
|
||||
'script-src': ['self', 'unsafe-inline'],
|
||||
'style-src': ['self', 'unsafe-inline'],
|
||||
'img-src': ['self', 'data:', 'blob:'],
|
||||
'connect-src': ['self', 'http://localhost:8000', 'https://*.ohmj.fr'],
|
||||
'font-src': ['self'],
|
||||
'object-src': ['none'],
|
||||
'frame-ancestors': ['none'],
|
||||
'base-uri': ['self'],
|
||||
'form-action': ['self']
|
||||
}
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user