Skip to content

Commit

Permalink
Added CSP HTTP Header to MP apache config
Browse files Browse the repository at this point in the history
Ticket: ENT-11472
Changelog: None
Signed-off-by: Mikita Pilinka <[email protected]>
  • Loading branch information
mineralsfree committed Jul 19, 2024
1 parent 3479c1b commit b99e9a3
Showing 1 changed file with 17 additions and 0 deletions.
17 changes: 17 additions & 0 deletions cfe_internal/enterprise/templates/httpd.conf.mustache
Original file line number Diff line number Diff line change
Expand Up @@ -207,6 +207,23 @@ LogLevel warn
Header always set X-Frame-Options DENY
Header always set X-Content-Type-Options nosniff

Header always set Content-Security-Policy \
"frame-ancestors 'self'; \
default-src 'self'; \
script-src 'self' 'unsafe-inline'; \
style-src 'self' 'unsafe-inline' fonts.googleapis.com; \
object-src 'none'; \
frame-src 'self'; \
child-src 'self'; \
img-src 'self' avatars.githubusercontent.com badges.gitter.im fonts.gstatic.com kiwiirc.com raw.githubusercontent.com; \
font-src 'self' data: fonts.googleapis.com fonts.gstatic.com; \
connect-src 'self' fonts.gstatic.com fonts.googleapis.com; \
manifest-src 'self'; \
base-uri 'self'; \
form-action 'self'; \
media-src 'self'; \
worker-src 'self';"

<FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
Expand Down

0 comments on commit b99e9a3

Please sign in to comment.