Skip to content

Commit db3b482

Browse files
committed
CSP fix
1 parent b753607 commit db3b482

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

server.js

+6-1
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,12 @@ app.use((req, res, next) => {
2424
res.header('Cache-control', 'public, max-age=0');
2525
res.header('Pragma', 'no-cache');
2626
res.setHeader('X-Frame-Options', 'DENY');
27-
res.setHeader('Content-Security-Policy', "frame-ancestors 'none'; *.topcoder-dev.com 'none'; *.topcoder.com 'none';");
27+
res.setHeader('Content-Security-Policy',
28+
"frame-ancestors 'none';" +
29+
"script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval'" +
30+
' https://uni-nav.topcoder-dev.com' +
31+
' https://uni-nav.topcoder.com'
32+
);
2833

2934
next();
3035
});

0 commit comments

Comments
 (0)