From 325355c09cfb7d90d53ae6a0480bfb6922ca5cf0 Mon Sep 17 00:00:00 2001 From: Avior Date: Mon, 12 Dec 2022 12:44:49 +0100 Subject: [PATCH] fix(config): incorrect config Signed-off-by: Avior --- packages/config/next.config.ts | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/packages/config/next.config.ts b/packages/config/next.config.ts index c68b0b7..7b46ce1 100644 --- a/packages/config/next.config.ts +++ b/packages/config/next.config.ts @@ -60,11 +60,11 @@ export const config = (options?: Options): typeof defaultConfig & NextConfig => "form-action 'self'; " + "manifest-src 'self'; " + "prefetch-src 'self'; " + - `script-src 'self' 'unsafe-inline' ${hosts?.script?.map((it) => `'${it}'`)?.join(' ') ?? ''}; ` + - `style-src 'self' 'unsafe-inline' ${hosts?.style?.map((it) => `'${it}'`)?.join(' ') ?? ''}; ` + - `img-src data: 'self' ${hosts?.img?.map((it) => `'${it}'`)?.join(' ') ?? ''}; ` + - `font-src 'self' ${hosts?.font?.map((it) => `'${it}'`)?.join(' ') ?? ''}; ` + - `connect-src 'self' ${hostlist.filter((it) => !it.startsWith('unsafe')).map((it) => `'${it}'`).join(' ')}; ` + + `script-src 'self' 'unsafe-inline' ${hosts?.script?.join(' ') ?? ''}; ` + + `style-src 'self' 'unsafe-inline' ${hosts?.style?.join(' ') ?? ''}; ` + + `img-src data: 'self' ${hosts?.img?.join(' ') ?? ''}; ` + + `font-src 'self' ${hosts?.font?.join(' ') ?? ''}; ` + + `connect-src 'self' ${hostlist.filter((it) => !it.startsWith('unsafe')).join(' ')}; ` + "base-uri 'self';" } const XXssProtection = {