File tree Expand file tree Collapse file tree 2 files changed +2
-2
lines changed Expand file tree Collapse file tree 2 files changed +2
-2
lines changed Original file line number Diff line number Diff line change 81
81
# See https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
82
82
# See https://content-security-policy.com/nonce/
83
83
# See https://angular.io/guide/security#content-security-policy
84
- add_header content-security-policy "default-src 'self'; style-src 'self' 'nonce-$cspNonce' ; script-src 'self' 'nonce-$cspNonce'; font-src 'self'; frame-src loginproxy.gov.bc.ca dev.loginproxy.gov.bc.ca test.loginproxy.gov.bc.ca; connect-src 'self' loginproxy.gov.bc.ca dev.loginproxy.gov.bc.ca test.loginproxy.gov.bc.ca server.arcgisonline.com; img-src 'self' https://tile.openstreetmap.org data: server.arcgisonline.com www.w3.org; frame-ancestors https://loginproxy.gov.bc.ca https://dev.loginproxy.gov.bc.ca https://test.loginproxy.gov.bc.ca; object-src 'none'; base-uri 'self'; form-action 'self';" ;
84
+ add_header content-security-policy "default-src 'self'; style-src 'self' 'nonce-$cspNonce' 'unsafe-hashes' ; script-src 'self' 'nonce-$cspNonce' 'unsafe-eval' ; font-src 'self'; frame-src 'self' https:// loginproxy.gov.bc.ca https:// dev.loginproxy.gov.bc.ca https:// test.loginproxy.gov.bc.ca; connect-src 'self' ws: wss: https:// loginproxy.gov.bc.ca https:// dev.loginproxy.gov.bc.ca https:// test.loginproxy.gov.bc.ca server.arcgisonline.com; img-src 'self' https://tile.openstreetmap.org data: server.arcgisonline.com www.w3.org; frame-ancestors https://loginproxy.gov.bc.ca https://dev.loginproxy.gov.bc.ca https://test.loginproxy.gov.bc.ca; object-src 'none'; base-uri 'self'; form-action 'self';" ;
85
85
86
86
include /nginx/nginx.conf;
87
87
Original file line number Diff line number Diff line change 79
79
# See https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
80
80
# See https://content-security-policy.com/nonce/
81
81
# See https://angular.io/guide/security#content-security-policy
82
- add_header content-security-policy "default-src 'self'; style-src 'self' 'nonce-$cspNonce' ; script-src 'self' 'nonce-$cspNonce'; font-src 'self'; frame-src loginproxy.gov.bc.ca dev.loginproxy.gov.bc.ca test.loginproxy.gov.bc.ca; connect-src 'self' loginproxy.gov.bc.ca dev.loginproxy.gov.bc.ca test.loginproxy.gov.bc.ca server.arcgisonline.com; img-src 'self' https://tile.openstreetmap.org data: server.arcgisonline.com www.w3.org; frame-ancestors https://loginproxy.gov.bc.ca https://dev.loginproxy.gov.bc.ca https://test.loginproxy.gov.bc.ca; object-src 'none'; base-uri 'self'; form-action 'self';";
82
+ add_header content-security-policy "default-src 'self'; style-src 'self' 'nonce-$cspNonce' 'unsafe-hashes' ; script-src 'self' 'nonce-$cspNonce' 'unsafe-eval' ; font-src 'self'; frame-src 'self' https:// loginproxy.gov.bc.ca https:// dev.loginproxy.gov.bc.ca https:// test.loginproxy.gov.bc.ca; connect-src 'self' ws: wss: https:// loginproxy.gov.bc.ca https:// dev.loginproxy.gov.bc.ca https:// test.loginproxy.gov.bc.ca server.arcgisonline.com; img-src 'self' https://tile.openstreetmap.org data: server.arcgisonline.com www.w3.org; frame-ancestors https://loginproxy.gov.bc.ca https://dev.loginproxy.gov.bc.ca https://test.loginproxy.gov.bc.ca; object-src 'none'; base-uri 'self'; form-action 'self';";
83
83
84
84
include /nginx/nginx.conf;
85
85
You can’t perform that action at this time.
0 commit comments