FIX: removed 'unsafe-inline' from content policy and cleaned up root HTML file.
This commit is contained in:
@@ -9,7 +9,7 @@
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=edge">
|
||||
<meta http-equiv="Content-Security-Policy" content="
|
||||
default-src 'self' 'unsafe-inline';
|
||||
default-src 'self';
|
||||
style-src 'self' https://fonts.googleapis.com https://cdn.jsdelivr.net;
|
||||
font-src 'self' https://cdn.jsdelivr.net https://fonts.gstatic.com;
|
||||
connect-src ws:;
|
||||
|
||||
Reference in New Issue
Block a user