Skip to content

Commit bbbef5e

Browse files
committed
fix: Embed CSP
1 parent de4ff38 commit bbbef5e

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

app/pages/embed/[chartId].tsx

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,17 @@ const EmbedPage = (props: PageProps) => {
6666
<Head>
6767
<meta
6868
httpEquiv="Content-Security-Policy"
69-
content="default-src 'self' 'unsafe-inline' data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://api.mapbox.com https://api.maptiler.com; style-src 'self' 'unsafe-inline';"
69+
content={[
70+
`default-src 'self' 'unsafe-inline' data: https://*.sentry.io https://vercel.live/ https://vercel.com https://*.googletagmanager.com`,
71+
`script-src 'unsafe-inline' 'unsafe-eval' 'self' https://api.mapbox.com https://api.maptiler.com https://*.sentry.io https://vercel.live/ https://vercel.com https://*.googletagmanager.com`,
72+
`style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net`,
73+
`font-src 'self'`,
74+
`form-action 'self'`,
75+
`connect-src 'self' *`,
76+
`img-src 'self' * data: blob:`,
77+
`script-src-elem 'self' 'unsafe-inline' https://*.admin.ch https://visualize.admin.ch https://*.visualize.admin.ch https://vercel.live https://vercel.com https://*.vercel.app https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://api.mapbox.com https://cdn.jsdelivr.net`,
78+
`worker-src 'self' blob: https://*.admin.ch https://*.vercel.app`,
79+
].join("; ")}
7080
/>
7181
</Head>
7282
<ConfiguratorStateProvider

0 commit comments

Comments
 (0)