fix: can't load external js because of Content Security Policy
This commit is contained in:
parent
903f2a2f8f
commit
f62ff2d51f
@ -5,12 +5,13 @@ const withBundleAnalyzer = require('@next/bundle-analyzer')({
|
||||
// You might need to insert additional domains in script-src if you are using external services
|
||||
const ContentSecurityPolicy = `
|
||||
default-src 'self';
|
||||
script-src 'self' 'unsafe-eval' 'unsafe-inline';
|
||||
script-src 'self' 'unsafe-eval' 'unsafe-inline' giscus.app;
|
||||
style-src 'self' 'unsafe-inline' *.googleapis.com cdn.jsdelivr.net;
|
||||
img-src * blob: data:;
|
||||
media-src 'none';
|
||||
connect-src *;
|
||||
font-src 'self' fonts.gstatic.com cdn.jsdelivr.net;
|
||||
frame-src giscus.app
|
||||
`
|
||||
|
||||
const securityHeaders = [
|
||||
|
Loading…
x
Reference in New Issue
Block a user