Fix header

This commit is contained in:
James Cole 2024-03-10 16:46:33 +01:00
parent 24e62b1cee
commit f12e502eb8
No known key found for this signature in database
GPG Key ID: B49A324B7EAD6D80

View File

@ -50,12 +50,12 @@ class SecureHeaders
$csp = [
"default-src 'none'",
"object-src 'none'",
sprintf("script-src 'unsafe-eval' 'strict-dynamic' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
sprintf("script-src 'unsafe-eval' 'strict-dynamic' 'nonce-%1s'", $nonce),
"style-src 'unsafe-inline' 'self'",
"base-uri 'self'",
"font-src 'self' data:",
sprintf("connect-src 'self' %s", $trackingScriptSrc),
sprintf("img-src 'strict-dynamic' 'self' %s", $trackingScriptSrc),
sprintf("img-src 'strict-dynamic' 'self' 'nonce-%1s'", $nonce),
"manifest-src 'self'",
];