mirror of
https://github.com/moparisthebest/mail
synced 2025-01-10 21:18:02 -05:00
fix csp for prdouction web server
This commit is contained in:
parent
01902f1fe4
commit
7b16d6b713
12
Gruntfile.js
12
Gruntfile.js
@ -20,20 +20,20 @@ module.exports = function(grunt) {
|
||||
prod: {
|
||||
options: {
|
||||
port: process.env.PORT || 8585,
|
||||
base: './src/',
|
||||
base: './dist/',
|
||||
keepalive: true,
|
||||
middleware: function(connect, options) {
|
||||
// Return array of whatever middlewares you want
|
||||
return [function(req, res, next) {
|
||||
res.setHeader('Content-Security-Policy', "default-src 'self'; script-src 'self' 'unsafe-eval'; connect-src *; object-src 'none'; style-src 'self' 'unsafe-inline'");
|
||||
res.setHeader('X-Content-Security-Policy', "default-src *; script-src 'self' 'unsafe-eval'; options eval-script; object-src 'none'; style-src 'self' 'unsafe-inline'");
|
||||
res.setHeader('X-WebKit-CSP', "default-src 'self'; script-src 'self' 'unsafe-eval'; connect-src *; object-src 'none'; style-src 'self' 'unsafe-inline'");
|
||||
return [
|
||||
function(req, res, next) {
|
||||
res.setHeader('Content-Security-Policy', "default-src 'self'; connect-src *; object-src 'none'; style-src 'self' 'unsafe-inline'");
|
||||
|
||||
return next();
|
||||
},
|
||||
|
||||
// Serve static files.
|
||||
connect.static(options.base)];
|
||||
connect.static(options.base)
|
||||
];
|
||||
}
|
||||
}
|
||||
}
|
||||
|
Loading…
Reference in New Issue
Block a user