From 891011682d66ce3c8410cd318cbb3145906b5834 Mon Sep 17 00:00:00 2001 From: Jonas Tobias Hopusch Date: Tue, 22 Feb 2022 12:44:59 +0100 Subject: [PATCH] Set CSP default to none and disable forms --- www.jotoho.de/Caddyfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/www.jotoho.de/Caddyfile b/www.jotoho.de/Caddyfile index 7dc7b78..c129323 100644 --- a/www.jotoho.de/Caddyfile +++ b/www.jotoho.de/Caddyfile @@ -1,6 +1,6 @@ http://www.jotoho.de -header Content-Security-Policy "default-src 'self'; base-uri 'self' https://jotoho.de https://*.jotoho.de; child-src 'none'; connect-src 'none'; font-src 'none'; frame-ancestors 'none'; img-src 'self' https://jotoho.de https://*.jotoho.de; media-src 'self' https://jotoho.de https://*.jotoho.de; object-src 'none'; plugin-types 'none'; style-src 'self'; worker-src 'none'; upgrade-insecure-requests;" +header Content-Security-Policy "default-src 'none'; base-uri 'self' https://jotoho.de https://*.jotoho.de; child-src 'none'; connect-src 'none'; font-src 'none'; frame-ancestors 'none'; img-src 'self' https://jotoho.de https://*.jotoho.de; media-src 'self' https://jotoho.de https://*.jotoho.de; object-src 'none'; plugin-types 'none'; style-src 'self'; worker-src 'none'; upgrade-insecure-requests; form-src 'none';" file_server { root /site/