Skip to content

Commit a25ff18

Browse files
committed
csp vylepšení
1 parent fd02a9a commit a25ff18

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

server/000-infinityloop.conf

+1-1
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ ServerSignature Off
4444
SSLCertificateKeyFile /etc/letsencrypt/live/infinityloop.cz/privkey.pem
4545

4646
Header always set Feature-Policy "accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none'"
47-
Header always set Content-Security-Policy "default-src 'none'; style-src 'self'; img-src 'self'; script-src 'none'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'"
47+
Header always set Content-Security-Policy "default-src 'none'; style-src 'self' https://fonts.googleapis.com/; font-src https://fonts.gstatic.com/; img-src 'self'; script-src 'none'; object-src 'none'; manifest-src: 'self'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'"
4848
Header always set X-XSS-Protection 1;mode=block
4949
Header always set X-Content-Type-Options nosniff
5050
Header always set X-Frame-Options SAMEORIGIN

0 commit comments

Comments
 (0)