Commit 86a6b665 authored by Jakob Moser's avatar Jakob Moser
Browse files

Make CSP really, really work (this time)

parent e3231c38
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -63,7 +63,7 @@ This virtual host simply redirects any HTTP request to the HTTPS endpoint.
        Header always set X-Frame-Options "SAMEORIGIN"
        Header always set Referrer-Policy "no-referrer"
        Header always set X-Content-Type-Options "nosniff"
        Header always set Content-Security-Policy "default-src 'self' https://tickets.technik.cl.uni-heidelberg.de; style-src 'self' 'unsafe-inline' https://tickets.technik.cl.uni-heidelberg.de data:; connect-src 'self' wss://tickets.technik.cl.uni-heidelberg.de"
        Header always set Content-Security-Policy "default-src 'self' https://tickets.technik.cl.uni-heidelberg.de; style-src 'self' 'unsafe-inline' https://tickets.technik.cl.uni-heidelberg.de data:; connect-src 'self' wss://tickets.technik.cl.uni-heidelberg.de; img-src 'self' http://tickets.technik.cl.uni-heidelberg.de https://tickets.technik.cl.uni-heidelberg.de"
</VirtualHost>
</IfModule>
```