Add CSP's connect-src directive to config (#547) (#548)

This commit is contained in:
Evgeniy Maynagashev
2021-03-29 20:53:59 +07:00
committed by GitHub
parent 982745144f
commit 002ebd46e4
2 changed files with 3 additions and 1 deletions

View File

@@ -90,6 +90,8 @@ stylesrc = [
]
scriptsrc = ["'self'", "'unsafe-inline'", "https://www.google-analytics.com"]
prefetchsrc = ["'self'"]
# connect-src directive defines valid targets for to XMLHttpRequest (AJAX), WebSockets or EventSource
connectsrc = ["'self'", "https://www.google-analytics.com"]
[taxonomies]
category = "categories"