From a9cd23b807e805c6383ae2be64ff9beecbde05c8 Mon Sep 17 00:00:00 2001 From: Bruno Bernardino Date: Thu, 30 Jun 2022 19:45:09 +0100 Subject: [PATCH] Fix CSP --- next.config.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/next.config.js b/next.config.js index 1c33b2e..7786930 100644 --- a/next.config.js +++ b/next.config.js @@ -9,7 +9,7 @@ const securityHeaders = [ { key: 'Content-Security-Policy', value: - "default-src 'self' https://*.userbase.com wss://*.userbase.com https://*.stripe.com data: blob:; child-src 'self' data: blob: https://*.stripe.com; img-src 'self' https://*.plausible.io data: blob: https://*.stripe.com; style-src 'self' 'unsafe-inline' https://*.stripe.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.plausible.io https://*.stripe.com", + "default-src 'self' https://*.userbase.com wss://*.userbase.com https://*.stripe.com data: blob:; child-src 'self' data: blob: https://*.stripe.com; img-src 'self' https://plausible.io data: blob: https://*.stripe.com; style-src 'self' 'unsafe-inline' https://*.stripe.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://plausible.io https://*.stripe.com", }, { key: 'Strict-Transport-Security',