This commit is contained in:
Aevann1 2021-12-08 19:40:36 +02:00
parent 3d52cbca0e
commit 94bfc9e745

View file

@ -125,7 +125,7 @@ def after_request(response):
response.headers.add("Strict-Transport-Security", "max-age=31536000")
response.headers.add("X-Frame-Options", "deny")
response.headers.add("Content-Security-Policy", "script-src 'self' *.cloudflare.com;")
response.headers.add("Content-Security-Policy", "script-src 'self' ajax.cloudflare.com 'unsafe-inline' static.cloudflareinsights.com; connect-src cloudflareinsights.co;")
return response