Updated CSP.
This commit is contained in:
@@ -19,7 +19,7 @@ const contentSecurityPolicy = `
|
|||||||
img-src 'self' https: data:;
|
img-src 'self' https: data:;
|
||||||
script-src 'self' 'unsafe-eval' 'unsafe-inline';
|
script-src 'self' 'unsafe-eval' 'unsafe-inline';
|
||||||
style-src 'self' 'unsafe-inline';
|
style-src 'self' 'unsafe-inline';
|
||||||
connect-src 'self' api.umami.is cloud.umami.is;
|
connect-src *;
|
||||||
frame-ancestors 'self' ${frameAncestors};
|
frame-ancestors 'self' ${frameAncestors};
|
||||||
`;
|
`;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user