fix(config): bad style-src and font-src

This commit is contained in:
Jason
2023-09-22 18:06:19 -07:00
parent 10c6d44e24
commit 95fbc16577

View File

@@ -6,13 +6,13 @@ const withBundleAnalyzer = require('@next/bundle-analyzer')({
// You might need to insert additional domains in script-src if you are using external services // You might need to insert additional domains in script-src if you are using external services
const ContentSecurityPolicy = ` const ContentSecurityPolicy = `
default-src 'self' fonts.gstatic.com; default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline' giscus.app analytics.umami.is; script-src 'self' 'unsafe-eval' 'unsafe-inline' giscus.app analytics.umami.is;
style-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' fonts.googleapis.com;
img-src * blob: data:; img-src * blob: data:;
media-src 'self'; media-src 'self';
connect-src *; connect-src *;
font-src 'self'; font-src 'self' fonts.gstatic.com;
frame-src giscus.app www.youtube.com; frame-src giscus.app www.youtube.com;
` `