Skip to content

Commit 22f40bb

Browse files
committed
remove style-src 'unsafe-inline' :)
1 parent cf0ea53 commit 22f40bb

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

vercel.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
"headers": [
88
{
99
"key": "content-security-policy",
10-
"value": "default-src 'self'; style-src 'unsafe-inline' 'self'; frame-src 'none'; object-src 'none'; form-action 'none'; frame-ancestors 'none'"
10+
"value": "default-src 'self'; frame-src 'none'; object-src 'none'; form-action 'none'; frame-ancestors 'none'"
1111
},
1212
{ "key": "x-content-type-options", "value": "nosniff" },
1313
{ "key": "x-frame-options", "value": "DENY" }

vite.config.ts

+1-1
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ const cspNonce = randomBytes(8).toString('hex')
8282
const csp = headers['content-security-policy']
8383
const devHeaders = {
8484
...headers,
85-
'content-security-policy': `${csp}; script-src 'nonce-${cspNonce}' 'self'`,
85+
'content-security-policy': `${csp}; script-src 'nonce-${cspNonce}' 'self'; style-src 'nonce-${cspNonce}' 'self'`,
8686
}
8787

8888
// see https://vitejs.dev/config/

0 commit comments

Comments
 (0)