Weird headers.

This commit is contained in:
James Cole 2021-04-08 12:05:08 +02:00
parent 4fa7a5c1bc
commit e580093a34
No known key found for this signature in database
GPG Key ID: B5669F9493CDE38D

View File

@ -54,7 +54,7 @@ class SecureHeaders
"default-src 'none'",
"object-src 'self'",
sprintf("script-src 'unsafe-inline' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
"frame-ancestors 'none'",
"style-src 'self' 'unsafe-inline'",
"base-uri 'self'",
"font-src 'self' data:",
"connect-src 'self'",