mirror of
https://github.com/firefly-iii/firefly-iii.git
synced 2025-02-25 18:45:27 -06:00
Disable almost all things.
This commit is contained in:
parent
e458208966
commit
3e12d26afd
@ -51,19 +51,17 @@ class SecureHeaders
|
|||||||
$response = $next($request);
|
$response = $next($request);
|
||||||
$trackingScriptSrc = $this->getTrackingScriptSource();
|
$trackingScriptSrc = $this->getTrackingScriptSource();
|
||||||
$csp = [
|
$csp = [
|
||||||
"default-src 'none'",
|
// "default-src 'none'",
|
||||||
"object-src 'self'",
|
// "object-src 'none'",
|
||||||
sprintf("script-src 'unsafe-inline' 'nonce-%1s' %2s 'strict-dynamic'", $nonce, $trackingScriptSrc),
|
// "require-trusted-types-for 'script'",
|
||||||
"style-src 'unsafe-inline' 'self'",
|
// sprintf("script-src 'unsafe-inline' 'strict-dynamic' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
|
||||||
"frame-ancestors 'none'",
|
// "style-src 'unsafe-inline' 'self'",
|
||||||
"base-uri 'self'",
|
// "frame-ancestors 'none'",
|
||||||
"font-src 'self' data:",
|
// "base-uri 'self'",
|
||||||
"connect-src 'self'",
|
// "font-src 'self' data:",
|
||||||
sprintf(
|
// "connect-src 'self'",
|
||||||
"img-src 'self' data: https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org https://api.tiles.mapbox.com %s",
|
// sprintf("img-src 'self' data: https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org https://api.tiles.mapbox.com %s", $trackingScriptSrc),
|
||||||
$trackingScriptSrc
|
// "manifest-src 'self'",
|
||||||
),
|
|
||||||
"manifest-src 'self'",
|
|
||||||
];
|
];
|
||||||
|
|
||||||
$route = $request->route();
|
$route = $request->route();
|
||||||
|
Loading…
Reference in New Issue
Block a user