Add a sane default CSP

This commit is contained in:
Alex Gleason 2025-06-04 13:07:41 -05:00
parent cd87b6e430
commit f146bf58d7
No known key found for this signature in database
GPG Key ID: 7211D1F99744FBB7

View File

@ -3,6 +3,7 @@
<head> <head>
<meta charset="UTF-8" /> <meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta http-equiv="content-security-policy" content="default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; frame-src 'self' https:; font-src 'self'; base-uri 'self'; manifest-src 'self'; connect-src 'self' blob: https: wss:; img-src 'self' data: blob: https:; media-src 'self' https:">
</head> </head>
<body> <body>
<div id="root"></div> <div id="root"></div>