From e9cf2e141b17710b56b0c25db2faf818fb191054 Mon Sep 17 00:00:00 2001 From: Kieran Date: Mon, 22 Jan 2024 16:58:15 +0000 Subject: [PATCH] chore: update _headers --- packages/app/public/nostr/_headers | 4 ++++ packages/app/public/snort/_headers | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 packages/app/public/nostr/_headers diff --git a/packages/app/public/nostr/_headers b/packages/app/public/nostr/_headers new file mode 100644 index 00000000..8ee864fe --- /dev/null +++ b/packages/app/public/nostr/_headers @@ -0,0 +1,4 @@ +/* + Content-Security-Policy: default-src 'self'; manifest-src *; child-src 'none'; worker-src 'self'; frame-src youtube.com www.youtube.com https://platform.twitter.com https://embed.tidal.com https://w.soundcloud.com https://www.mixcloud.com https://open.spotify.com https://player.twitch.tv https://embed.music.apple.com https://embed.wavlake.com https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; connect-src *; img-src * data: blob:; font-src 'self'; media-src * blob:; script-src 'self' 'wasm-unsafe-eval' https://platform.twitter.com https://embed.tidal.com https://challenges.cloudflare.com; + Cross-Origin-Opener-Policy: same-origin + Cross-Origin-Embedder-Policy: require-corp \ No newline at end of file diff --git a/packages/app/public/snort/_headers b/packages/app/public/snort/_headers index fc7a5a34..8ee864fe 100644 --- a/packages/app/public/snort/_headers +++ b/packages/app/public/snort/_headers @@ -1,4 +1,4 @@ /* - Content-Security-Policy: default-src 'self'; manifest-src *; child-src 'none'; worker-src 'self'; frame-src youtube.com www.youtube.com https://platform.twitter.com https://embed.tidal.com https://w.soundcloud.com https://www.mixcloud.com https://open.spotify.com https://player.twitch.tv https://embed.music.apple.com https://nostrnests.com https://embed.wavlake.com https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; connect-src *; img-src * data: blob:; font-src 'self'; media-src * blob:; script-src 'self' 'wasm-unsafe-eval' https://analytics.v0l.io https://platform.twitter.com https://embed.tidal.com https://challenges.cloudflare.com; + Content-Security-Policy: default-src 'self'; manifest-src *; child-src 'none'; worker-src 'self'; frame-src youtube.com www.youtube.com https://platform.twitter.com https://embed.tidal.com https://w.soundcloud.com https://www.mixcloud.com https://open.spotify.com https://player.twitch.tv https://embed.music.apple.com https://embed.wavlake.com https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; connect-src *; img-src * data: blob:; font-src 'self'; media-src * blob:; script-src 'self' 'wasm-unsafe-eval' https://platform.twitter.com https://embed.tidal.com https://challenges.cloudflare.com; Cross-Origin-Opener-Policy: same-origin Cross-Origin-Embedder-Policy: require-corp \ No newline at end of file