Commit 253d3cf299
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/nginx.conf +9 −1
| @@ -143,7 +143,15 @@ http { | ||
| 143 | 143 | # Add Content-Security-Policy for HTML documents. |
| 144 | 144 | # custom.d/security/content-security-policy.conf |
| 145 | 145 | map $sent_http_content_type $content_security_policy { |
| 146 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests"; | |
| 146 | ~*text/(html|javascript)|application/pdf|xml " | |
| 147 | default-src 'self'; | |
| 148 | img-src 'self' https://img.cleberg.net; | |
| 149 | base-uri 'none'; | |
| 150 | form-action 'self'; | |
| 151 | frame-ancestors 'none'; | |
| 152 | object-src 'none'; | |
| 153 | upgrade-insecure-requests | |
| 154 | "; | |
| 147 | 155 | } |
| 148 | 156 | |
| 149 | 157 | # Add Permissions-Policy for HTML documents. |