Update headers

This commit is contained in:
James Cole
2021-04-08 11:58:21 +02:00
parent d668007fee
commit 4fa7a5c1bc

View File

@@ -53,7 +53,7 @@ class SecureHeaders
$csp = [
"default-src 'none'",
"object-src 'self'",
sprintf("script-src 'unsafe-inline' 'nonce-%1s' %2s 'strict-dynamic'", $nonce, $trackingScriptSrc),
sprintf("script-src 'unsafe-inline' 'nonce-%1s' %2s", $nonce, $trackingScriptSrc),
"frame-ancestors 'none'",
"base-uri 'self'",
"font-src 'self' data:",