Update dev mode settings.

This commit is contained in:
James Cole
2026-03-14 07:31:16 +01:00
parent b8ebcdf1a8
commit b9d1ed28a5

View File

@@ -74,8 +74,8 @@ class SecureHeaders
"default-src 'none'",
"object-src 'none'",
sprintf("script-src 'unsafe-eval' 'strict-dynamic' 'nonce-%1s'", $nonce),
sprintf("style-src 'self' 'nonce-%1s' https://10.0.0.15:5173/", $nonce), // safe variant
// "style-src 'self' 'unsafe-inline' https://10.0.0.15:5173/", // unsafe variant
// sprintf("style-src 'self' 'nonce-%1s' https://10.0.0.15:5173/", $nonce), // safe variant
"style-src 'self' 'unsafe-inline' https://10.0.0.15:5173/", // unsafe variant
"base-uri 'self'",
"form-action 'self'",
"font-src 'self' data: https://10.0.0.15:5173/",