|
13 | 13 | #
|
14 | 14 | # :unsafe_eval, allows execution of eval statements
|
15 | 15 | # :unsafe_inline, allows inline resources usage
|
| 16 | + FRONTEND_URL = 'http://localhost:4200' |
16 | 17 |
|
17 | 18 | policy.default_src :none unless Rails.env.development?
|
18 | 19 | policy.font_src :self, "http://localhost:4200/text-security-disc-compat.eot?#iefix",
|
|
22 | 23 | policy.connect_src :self, 'https://sentry.puzzle.ch'
|
23 | 24 |
|
24 | 25 | policy.font_src :self
|
25 |
| - policy.font_src :self, :https, 'http://localhost:4200', :data if Rails.env.development? |
| 26 | + policy.font_src :self, :https, FRONTEND_URL, :data if Rails.env.development? |
26 | 27 |
|
27 | 28 | policy.script_src :self
|
28 |
| - policy.script_src :self, :unsafe_eval, "http://localhost:4200" if Rails.env.development? |
| 29 | + policy.script_src :self, :unsafe_eval, FRONTEND_URL if Rails.env.development? |
29 | 30 |
|
30 | 31 | policy.style_src :self, :unsafe_inline
|
31 |
| - policy.style_src :self, :unsafe_inline, "http://localhost:4200" if Rails.env.development? |
| 32 | + policy.style_src :self, :unsafe_inline, FRONTEND_URL if Rails.env.development? |
32 | 33 |
|
33 | 34 | # If you are using webpack-dev-server then specify webpack-dev-server host
|
34 | 35 | policy.connect_src :self, "http://localhost:3035", "ws://localhost:4200" if Rails.env.development?
|
|
0 commit comments