mirror of
https://github.com/zitadel/zitadel.git
synced 2025-08-11 20:37:30 +00:00
fix(console): add style / font src hosts to connect src (#259)
This commit is contained in:
@@ -65,7 +65,10 @@ func csp(zitadelDomain string) *middleware.CSP {
|
||||
csp.StyleSrc = csp.StyleSrc.AddInline().AddHost("fonts.googleapis.com").AddHost("maxst.icons8.com") //TODO: host it
|
||||
csp.FontSrc = csp.FontSrc.AddHost("fonts.gstatic.com").AddHost("maxst.icons8.com") //TODO: host it
|
||||
csp.ScriptSrc = csp.ScriptSrc.AddEval()
|
||||
csp.ConnectSrc = csp.ConnectSrc.AddHost(zitadelDomain)
|
||||
csp.ConnectSrc = csp.ConnectSrc.AddHost(zitadelDomain).
|
||||
AddHost("fonts.googleapis.com").
|
||||
AddHost("fonts.gstatic.com").
|
||||
AddHost("maxst.icons8.com") //TODO: host it
|
||||
return &csp
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user