add back connect-src 'self' for Lighthouse
This reverts commit d30566d8f6.
This is needed by Lighthouse to fetch robots.txt and it's worth making a
harmless exception for it to work properly.
https://github.com/GoogleChrome/lighthouse/issues/4386
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
Options -indexes
|
Options -indexes
|
||||||
|
|
||||||
Header always set Content-Security-Policy "default-src 'none'; connect-src https://seamlessupdate.app/; \
|
Header always set Content-Security-Policy "default-src 'none'; connect-src 'self' https://seamlessupdate.app/; \
|
||||||
font-src 'self'; img-src 'self'; manifest-src 'self'; script-src 'self'; style-src 'self'; \
|
font-src 'self'; img-src 'self'; manifest-src 'self'; script-src 'self'; style-src 'self'; \
|
||||||
form-action 'none'; frame-ancestors 'none'; block-all-mixed-content; base-uri 'none'; \
|
form-action 'none'; frame-ancestors 'none'; block-all-mixed-content; base-uri 'none'; \
|
||||||
report-uri https://danielmicay.report-uri.com/r/d/csp/enforce"
|
report-uri https://danielmicay.report-uri.com/r/d/csp/enforce"
|
||||||
|
|||||||
Reference in New Issue
Block a user