make CSP even a little bit more restrictive

This commit is contained in:
jelhan 2016-09-03 18:51:38 +02:00
parent 4bb85a1381
commit 3cf26d7221
3 changed files with 6 additions and 6 deletions

View file

@ -17,9 +17,9 @@ module.exports = function(environment) {
'script-src': "'self'",
'font-src': "'self'",
'connect-src': "'self'",
'img-src': "'self'",
'img-src': "'none'",
'style-src': "'self'",
'media-src': "'self'",
'media-src': "'none'",
'referrer': "no-referrer"
},

View file

@ -39,7 +39,7 @@
"ember-cli-build-info": "^0.2.0",
"ember-cli-chart": "git://github.com/jelhan/ember-cli-chart.git#52ae694db579df94e0ef057d2cf7d6d96c61f78f",
"ember-cli-clipboard": "0.4.1",
"ember-cli-content-security-policy": "0.4.0",
"ember-cli-content-security-policy": "0.5.0",
"ember-cli-dependency-checker": "^1.2.0",
"ember-cli-flash": "1.3.16",
"ember-cli-htmlbars": "^1.0.1",

View file

@ -1,5 +1,5 @@
# Content Security Policy-Headers
# you have to enable apache module headers to get them working
#Header set Content-Security-Policy "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; referrer no-referrer;"
#Header set X-Content-Security-Policy "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; referrer no-referrer;"
#Header set X-Webkit-CSP "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; referrer no-referrer;"
#Header set Content-Security-Policy "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; style-src 'self'; referrer no-referrer;"
#Header set X-Content-Security-Policy "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; style-src 'self'; referrer no-referrer;"
#Header set X-Webkit-CSP "default-src 'none'; script-src 'self'; font-src 'self'; connect-src 'self'; style-src 'self'; referrer no-referrer;"