|
|
@ -19,7 +19,7 @@ map $request_uri $csp_header { |
|
|
|
# - "https://js.stripe.com" in script-src and frame-src is needed for Stripe |
|
|
|
"~^/donate_stripe$" "default-src 'none'; script-src 'self' https://js.stripe.com; style-src 'self'; img-src 'self' data:; connect-src 'self'; manifest-src 'self'; frame-src 'self' https://js.stripe.com; form-action 'self'; frame-ancestors 'none'; base-uri 'none'"; |
|
|
|
# The CSP for the OpenAPI (Swagger) UI page: |
|
|
|
# - "https://cdnjs.cloudflare.com" in script-src and style-src is needed for Swagger UI |
|
|
|
# - "https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/" in script-src and style-src is needed for Swagger UI |
|
|
|
"~^/api/beta/ui$" "default-src 'none'; script-src 'self' https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/; style-src 'self' https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/; img-src 'self' data:; connect-src 'self'; manifest-src 'self'; form-action 'self'; frame-ancestors 'none'; base-uri 'none'"; |
|
|
|
} |
|
|
|
|
|
|
|