Skip to content

Commit 3d60399

Browse files
committed
fix(frontend): fix CSP header
1 parent a1cf1fc commit 3d60399

File tree

6 files changed

+6
-6
lines changed

6 files changed

+6
-6
lines changed

src/ic_message_frontend/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,5 +85,5 @@
8585
"test": "vitest run"
8686
},
8787
"type": "module",
88-
"version": "2.13.2"
88+
"version": "2.13.3"
8989
}

src/ic_message_frontend/src/lib/constants.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
const src = globalThis.location?.href || ''
22

3-
export const APP_VERSION = '2.13.2'
3+
export const APP_VERSION = '2.13.3'
44
export const IS_LOCAL = src.includes('localhost') || src.includes('127.0.0.1')
55
export const ENV = IS_LOCAL ? 'local' : 'ic'
66
export const APP_ORIGIN = IS_LOCAL

src/ic_message_frontend/static/.ic-assets.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
"match": "**/*",
1616
"security_policy": "standard",
1717
"headers": {
18-
"Content-Security-Policy": "default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline';connect-src 'self' http://localhost:* https://icp0.io https://*.icp0.io https://icp-api.io;img-src 'self' https://pbs.twimg.com https://*.icp0.io data: blob:;style-src * 'unsafe-inline';style-src-elem * 'unsafe-inline';font-src *;object-src 'none';base-uri 'self';frame-ancestors 'none';form-action 'self';upgrade-insecure-requests;",
18+
"Content-Security-Policy": "default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline';connect-src 'self' http://localhost:* https://icp0.io https://*.icp0.io https://icp-api.io https://api.icpswap.com;img-src 'self' https://pbs.twimg.com https://*.icp0.io data: blob:;style-src * 'unsafe-inline';style-src-elem * 'unsafe-inline';font-src *;object-src 'none';base-uri 'self';frame-ancestors 'none';form-action 'self';upgrade-insecure-requests;",
1919
"Permissions-Policy": "autoplay=*, camera=*, cross-origin-isolated=*, display-capture=*, encrypted-media=*, fullscreen=*, keyboard-map=*, microphone=*, payment=*, picture-in-picture=*, clipboard-read=*, clipboard-write=*",
2020
"X-Frame-Options": "DENY",
2121
"Referrer-Policy": "same-origin",

src/ic_panda_frontend/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,5 +78,5 @@
7878
"test": "vitest run"
7979
},
8080
"type": "module",
81-
"version": "2.13.2"
81+
"version": "2.13.3"
8282
}

src/ic_panda_frontend/src/lib/constants.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
const src = globalThis.location?.href || ''
22

3-
export const APP_VERSION = '2.13.2'
3+
export const APP_VERSION = '2.13.3'
44
export const IS_LOCAL = src.includes('localhost') || src.includes('127.0.0.1')
55
export const ENV = IS_LOCAL ? 'local' : 'ic'
66
export const APP_ORIGIN = IS_LOCAL

src/ic_panda_frontend/static/.ic-assets.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
"match": "**/*",
1616
"security_policy": "standard",
1717
"headers": {
18-
"Content-Security-Policy": "default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline';connect-src 'self' http://localhost:* https://icp0.io https://*.icp0.io https://icp-api.io https://*.panda.fans;img-src 'self' https://pbs.twimg.com https://*.icp0.io data: blob:;style-src * 'unsafe-inline';style-src-elem * 'unsafe-inline';font-src *;object-src 'none';base-uri 'self';frame-ancestors 'none';frame-src;form-action 'self';upgrade-insecure-requests;",
18+
"Content-Security-Policy": "default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline';connect-src 'self' http://localhost:* https://icp0.io https://*.icp0.io https://icp-api.io https://api.icpswap.com https://*.panda.fans;img-src 'self' https://pbs.twimg.com https://*.icp0.io data: blob:;style-src * 'unsafe-inline';style-src-elem * 'unsafe-inline';font-src *;object-src 'none';base-uri 'self';frame-ancestors 'none';frame-src;form-action 'self';upgrade-insecure-requests;",
1919
"Permissions-Policy": "autoplay=*, camera=*, cross-origin-isolated=*, display-capture=*, encrypted-media=*, fullscreen=*, keyboard-map=*, microphone=*, payment=*, picture-in-picture=*, clipboard-read=*, clipboard-write=*",
2020
"X-Frame-Options": "DENY",
2121
"Referrer-Policy": "same-origin",

0 commit comments

Comments
 (0)