Skip to content

Commit

Permalink
[FIX] MiddlewareManager: Update SAP Target CSP Policies
Browse files Browse the repository at this point in the history
  • Loading branch information
RandomByte committed Jun 17, 2020
1 parent 1e1644a commit 269c22c
Showing 1 changed file with 16 additions and 8 deletions.
24 changes: 16 additions & 8 deletions lib/middleware/MiddlewareManager.js
Original file line number Diff line number Diff line change
Expand Up @@ -96,19 +96,27 @@ class MiddlewareManager {
"script-src 'self' 'unsafe-eval'; " +
"style-src 'self' 'unsafe-inline'; " +
"font-src 'self' data:; " +
"img-src 'self' * data: blob:; " +
"frame-src 'self' https: data: blob:; " +
"child-src 'self' https: data: blob:; " +
"connect-src 'self' https: wss:;",
"img-src 'self' https: http: data: blob:; " +
"media-src 'self' https: http: data: blob:; " +
"object-src blob:; " +
"frame-src 'self' https: gap: data: blob: mailto: tel:; " +
"worker-src 'self' blob:; " +
"child-src 'self' blob:; " +
"connect-src 'self' https: wss:; " +
"base-uri 'self';",
"sap-target-level-2":
"default-src 'self'; " +
"script-src 'self'; " +
"style-src 'self' 'unsafe-inline'; " +
"font-src 'self' data:; " +
"img-src 'self' * data: blob:; " +
"frame-src 'self' https: data: blob:; " +
"child-src 'self' https: data: blob:; " +
"connect-src 'self' https: wss:;"
"img-src 'self' https: http: data: blob:; " +
"media-src 'self' https: http: data: blob:; " +
"object-src blob:; " +
"frame-src 'self' https: gap: data: blob: mailto: tel:; " +
"worker-src 'self' blob:; " +
"child-src 'self' blob:; " +
"connect-src 'self' https: wss:; " +
"base-uri 'self';"
}
};
if (this.options.sendSAPTargetCSP) {
Expand Down

0 comments on commit 269c22c

Please sign in to comment.