update further

This commit is contained in:
Ben Rog-Wilhelm 2023-09-11 02:21:38 -05:00
parent 2e38627072
commit 0c9b025e08

View file

@ -52,10 +52,10 @@ def teardown_request(error):
@app.after_request
def after_request(response: Response):
response.headers.add("Content-Security-Policy", (
"script-src 'self' 'unsafe-inline';"
" script-src: 'self' https://*.googletagmanager.com"
" img-src: https://*.google-analytics.com https://*.googletagmanager.com"
" connect-src: 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com"
" object-src: 'none'"
))
response.headers.add("Strict-Transport-Security", "max-age=31536000")
response.headers.add("X-Frame-Options", "deny")