Skip to content

Commit

Permalink
chore: update address permissions (security)
Browse files Browse the repository at this point in the history
  • Loading branch information
HMarzban committed Aug 12, 2024
1 parent 69143cc commit dd383be
Showing 1 changed file with 13 additions and 13 deletions.
26 changes: 13 additions & 13 deletions packages/webapp/next.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -53,11 +53,11 @@ module.exports = withPWA({
'*.supabase.co',
'*.docs.plus',
'*.localhost',
process.env.NEXT_PUBLIC_RESTAPI_URL,
process.env.NEXT_PUBLIC_PROVIDER_URL,
process.env.NEXT_PUBLIC_SUPABASE_URL,
process.env.NEXT_PUBLIC_SUPABASE_WS_URL
]
process.env.NEXT_PUBLIC_RESTAPI_URL || '',
process.env.NEXT_PUBLIC_PROVIDER_URL || '',
process.env.NEXT_PUBLIC_SUPABASE_URL || '',
process.env.NEXT_PUBLIC_SUPABASE_WS_URL || ''
].filter(Boolean) // Filters out any empty strings

return [
{
Expand All @@ -66,15 +66,15 @@ module.exports = withPWA({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'", "'unsafe-inline'", "'unsafe-eval'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: allowAddress,
connectSrc: allowAddress,
fontSrc: ["'self'", 'data:'],
scriptSrc: ["'self'", "'unsafe-inline'", "'unsafe-eval'", ...allowAddress],
styleSrc: ["'self'", "'unsafe-inline'", ...allowAddress],
imgSrc: [...allowAddress, '*'],
connectSrc: [...allowAddress, '*'],
fontSrc: ["'self'", 'data:', '*'],
objectSrc: ["'none'"],
frameSrc: ["'self'"],
frameAncestors: ["'self'"],
formAction: ["'self'"],
frameSrc: ["'self'", ...allowAddress],
frameAncestors: ["'self'", ...allowAddress],
formAction: ["'self'", ...allowAddress],
upgradeInsecureRequests: []
}
},
Expand Down

0 comments on commit dd383be

Please sign in to comment.