changeset 202:1b93429d28b8 puppet-3.6

Allow locally hosted fonts in Content-Security-Policy
author IBBoard <dev@ibboard.co.uk>
date Mon, 27 May 2019 20:08:57 +0100
parents 80b2fdd7ddfd
children 6813609829e3
files modules/website/files/zzz-0-custom.conf
diffstat 1 files changed, 1 insertions(+), 1 deletions(-) [+]
line wrap: on
line diff
--- a/modules/website/files/zzz-0-custom.conf	Mon May 27 11:28:31 2019 +0100
+++ b/modules/website/files/zzz-0-custom.conf	Mon May 27 20:08:57 2019 +0100
@@ -92,5 +92,5 @@
 Header always set Referrer-Policy "no-referrer-when-downgrade"
 Header always set Expect-CT "max-age=0, report-uri='https://ibboard.report-uri.io/r/default/ct/reportOnly'"
 Header always set Content-Security-Policy "upgrade-insecure-requests"
-Header always set Content-Security-Policy-Report-Only "default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'"
+Header always set Content-Security-Policy-Report-Only "default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'; font-src 'self'"
 #; report-uri https://ibboard.report-uri.com/r/d/csp/reportOnly"
\ No newline at end of file