Skip to content

Commit

Permalink
Content-Security-Policy added to demos
Browse files Browse the repository at this point in the history
  • Loading branch information
enchev committed Sep 11, 2024
1 parent b1b6499 commit 9c3490f
Show file tree
Hide file tree
Showing 2 changed files with 22 additions and 0 deletions.
11 changes: 11 additions & 0 deletions RadzenBlazorDemos.Host/App.razor
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,17 @@
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta http-equiv="Content-Security-Policy"
content="base-uri 'self';
default-src 'self' unsafe-inline http://localhost:* ws://localhost:*;
connect-src 'self' https: wss: http://localhost:* ws://localhost:*;
img-src data: https:;
object-src 'none';
script-src 'self' 'unsafe-eval' 'unsafe-inline' http://localhost:* cdnjs.cloudflare.com cdn.syndication.twimg.com platform.linkedin.com www.linkedin.com analytics.radzen.com;
style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com;
font-src 'self' data: cdnjs.cloudflare.com;
frame-src www.youtube.com platform.twitter.com platform.linkedin.com www.linkedin.com;
upgrade-insecure-requests;">
<base href="/" />
<link href="css/site.css" rel="stylesheet" />
<HeadOutlet @rendermode="InteractiveWebAssembly" />
Expand Down
11 changes: 11 additions & 0 deletions RadzenBlazorDemos.Server/App.razor
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,17 @@
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta http-equiv="Content-Security-Policy"
content="base-uri 'self';
default-src 'self' unsafe-inline http://localhost:* ws://localhost:*;
connect-src 'self' https: wss: http://localhost:* ws://localhost:*;
img-src data: https:;
object-src 'none';
script-src 'self' 'unsafe-eval' 'unsafe-inline' http://localhost:* cdnjs.cloudflare.com cdn.syndication.twimg.com platform.linkedin.com www.linkedin.com analytics.radzen.com;
style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com;
font-src 'self' data: cdnjs.cloudflare.com;
frame-src www.youtube.com platform.twitter.com platform.linkedin.com www.linkedin.com;
upgrade-insecure-requests;">
<base href="/" />
<link href="css/site.css" rel="stylesheet" />
<HeadOutlet @rendermode="InteractiveServer" />
Expand Down

0 comments on commit 9c3490f

Please sign in to comment.