feat(csp): 🔒 add "base uri" csp security options

This commit is contained in:
Julien Oculi 2024-07-09 14:02:23 +02:00
parent e4fc9d22ae
commit 494c6b3a9f

View file

@ -16,6 +16,7 @@ export function useCsp(
upgradeInsecureRequests: true, upgradeInsecureRequests: true,
styleSrc: [...trustedDomains, "'unsafe-inline'"], //set nonce to inline script styleSrc: [...trustedDomains, "'unsafe-inline'"], //set nonce to inline script
manifestSrc: [`${ctx.url.origin}/manifest.json`], manifestSrc: [`${ctx.url.origin}/manifest.json`],
baseUri: ["'none'"],
imgSrc: [ imgSrc: [
...trustedDomains, ...trustedDomains,
'data:', 'data:',