fix: update Content Security Policy to allow Cloudflare Turnstile scripts

This commit is contained in:
Radosław Gierwiało
2025-12-06 15:03:36 +01:00
parent 68f8322221
commit dc6b3b30d0

View File

@@ -18,13 +18,13 @@ app.use(helmet({
directives: { directives: {
defaultSrc: ["'self'"], defaultSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'", "https://ui-avatars.com"], styleSrc: ["'self'", "'unsafe-inline'", "https://ui-avatars.com"],
scriptSrc: ["'self'"], scriptSrc: ["'self'", "https://challenges.cloudflare.com"],
imgSrc: ["'self'", "data:", "https:", "https://ui-avatars.com"], imgSrc: ["'self'", "data:", "https:", "https://ui-avatars.com"],
connectSrc: ["'self'"], connectSrc: ["'self'", "https://challenges.cloudflare.com"],
fontSrc: ["'self'"], fontSrc: ["'self'"],
objectSrc: ["'none'"], objectSrc: ["'none'"],
mediaSrc: ["'self'"], mediaSrc: ["'self'"],
frameSrc: ["'none'"], frameSrc: ["'self'", "https://challenges.cloudflare.com"],
}, },
}, },
hsts: { hsts: {