add Content Security Policy (#1252)
* add Content Security Policy * remove reflect-metadata on production builds to get rid of unsafe-eval * fix baseCSP usage * add SRI to CSP * add blob: to media-src * remove SRI * CSP set to reportOnly * adding data: to connect-src CSP * remove block-all-mixed-content * add report-uri support
Showing
- client/src/environments/environment.ts 7 additions, 0 deletionsclient/src/environments/environment.ts
- client/src/polyfills.ts 7 additions, 1 deletionclient/src/polyfills.ts
- config/default.yaml 2 additions, 0 deletionsconfig/default.yaml
- config/production.yaml.example 2 additions, 0 deletionsconfig/production.yaml.example
- server.ts 3 additions, 0 deletionsserver.ts
- server/controllers/client.ts 2 additions, 1 deletionserver/controllers/client.ts
- server/initializers/constants.ts 1 addition, 0 deletionsserver/initializers/constants.ts
- server/middlewares/csp.ts 45 additions, 0 deletionsserver/middlewares/csp.ts
- server/middlewares/dnt.ts 1 addition, 1 deletionserver/middlewares/dnt.ts
- server/middlewares/index.ts 2 additions, 0 deletionsserver/middlewares/index.ts
- support/docker/production/config/custom-environment-variables.yaml 3 additions, 1 deletion...ocker/production/config/custom-environment-variables.yaml
Loading
Please register or sign in to comment