Add additional sources in CSP header

This commit is contained in:
Luc Juggery 2018-02-02 15:15:47 +01:00
parent 429db13937
commit 1f0eeaeedf
3 changed files with 6 additions and 3 deletions

View file

@ -1,7 +1,8 @@
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="default-src 'self';script-src www.googletagmanager.com 'unsafe-inline';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<meta http-equiv="Content-Security-Policy"
content="default-src maxcdn.bootstrapcdn.com 'self';script-src code.jquery.com cdn.jsdelivr.net www.googletagmanager.com 'unsafe-inline' 'self';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self';font-src fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-113065209-1"></script>
<script>
window.dataLayer = window.dataLayer || [];

View file

@ -1,7 +1,8 @@
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="default-src 'self';script-src www.googletagmanager.com 'unsafe-inline';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<meta http-equiv="Content-Security-Policy"
content="default-src maxcdn.bootstrapcdn.com 'self';script-src code.jquery.com cdn.jsdelivr.net www.googletagmanager.com 'unsafe-inline' 'self';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self';font-src fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-113065209-1"></script>
<script>
window.dataLayer = window.dataLayer || [];

View file

@ -1,7 +1,8 @@
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="default-src 'self';script-src www.googletagmanager.com 'unsafe-inline';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<meta http-equiv="Content-Security-Policy"
content="default-src maxcdn.bootstrapcdn.com 'self';script-src code.jquery.com cdn.jsdelivr.net www.googletagmanager.com 'unsafe-inline' 'self';style-src fonts.googleapis.com maxcdn.bootstrapcdn.com 'self';font-src fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self'">
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-113065209-1"></script>
<script>
window.dataLayer = window.dataLayer || [];