# HG changeset patch # User IBBoard # Date 1558984137 -3600 # Node ID 1b93429d28b8eec1d44f136aab3c6a5f6e95f8fe # Parent 80b2fdd7ddfda4cc55699e04bf6e1b7ce036c32a Allow locally hosted fonts in Content-Security-Policy diff -r 80b2fdd7ddfd -r 1b93429d28b8 modules/website/files/zzz-0-custom.conf --- a/modules/website/files/zzz-0-custom.conf Mon May 27 11:28:31 2019 +0100 +++ b/modules/website/files/zzz-0-custom.conf Mon May 27 20:08:57 2019 +0100 @@ -92,5 +92,5 @@ Header always set Referrer-Policy "no-referrer-when-downgrade" Header always set Expect-CT "max-age=0, report-uri='https://ibboard.report-uri.io/r/default/ct/reportOnly'" Header always set Content-Security-Policy "upgrade-insecure-requests" -Header always set Content-Security-Policy-Report-Only "default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'" +Header always set Content-Security-Policy-Report-Only "default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'; font-src 'self'" #; report-uri https://ibboard.report-uri.com/r/d/csp/reportOnly" \ No newline at end of file