diff --git a/up/settings/base.py b/up/settings/base.py index c417a263..e73a1e04 100644 --- a/up/settings/base.py +++ b/up/settings/base.py @@ -185,9 +185,10 @@ CSPURL_SENTRY = "https://sentry.io" CSP_SELF = "'self'" +CSP_NONE = "'none'" # CSP konfigurace -CSP_DEFAULT_SRC = ("'none'",) +CSP_DEFAULT_SRC = (CSP_NONE,) CSP_STYLE_SRC = ( CSP_SELF, "'unsafe-inline'", @@ -197,3 +198,6 @@ CSP_SCRIPT_SRC = (CSP_SELF, CSPURL_SENTRY, CSPURL_GOOGLE_ANALYTICS, CSPURL_GOOGLE_ANALYTICS_SSL) CSP_FONT_SRC = (CSP_SELF, CSPURL_GOOGLE_FONTS_FONT) CSP_IMG_SRC = (CSP_SELF, CSPURL_GOOGLE_ANALYTICS, "data:") +CSP_FRAME_ANCESTORS = (CSP_NONE,) +CSP_FORM_ACTION = (CSP_NONE,) +CSP_BASE_URI = (CSP_NONE,)