Fix CSP for newsletter sign-up

This commit is contained in:
Stuart Colville 2019-03-28 11:47:40 +00:00
Родитель 2374ed045a
Коммит beb2a1b1ca
1 изменённых файлов: 2 добавлений и 2 удалений

Просмотреть файл

@ -34,9 +34,9 @@ CSPSTATIC="\"content-security-policy\": \"default-src 'none'; "\
"object-src 'none'\""
CSP="\"content-security-policy\": \"default-src 'none'; "\
"base-uri 'self'; "\
"connect-src https://blog.mozilla.org/addons/feed/ https://www.mozilla.org/newsletter/ https://www.google-analytics.com/; "\
"connect-src https://blog.mozilla.org/addons/feed/ https://www.mozilla.org/en-US/newsletter/ https://www.google-analytics.com/; "\
"font-src 'self'; "\
"form-action https://www.mozilla.org/newsletter/; "\
"form-action https://www.mozilla.org/en-US/newsletter/; "\
"frame-ancestors 'none'; "\
"frame-src https://www.youtube.com/embed/; "\
"img-src 'self' data:; "\