More permissive CORS policies.

This commit is contained in:
Bob Vandevliet 2025-07-05 11:34:15 +02:00
parent 66f9461569
commit 2909fd6c40

View file

@ -6,7 +6,16 @@
<meta http-equiv="Content-Security-Policy" content="
default-src 'self';
script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://cdn.jsdelivr.net https://*.fontawesome.com;
script-src 'self' 'unsafe-inline'
https://www.googletagmanager.com
https://cdn.jsdelivr.net
https://*.fontawesome.com;
media-src 'self'
https://www.youtube.com https://youtu.be
https://www.linkedin.com;
frame-src 'self'
https://www.youtube.com/embed/ https://youtu.be/embed/
https://www.linkedin.com/embed/;
style-src 'self' 'unsafe-inline' https://*.fontawesome.com;
font-src 'self' https://*.fontawesome.com;
connect-src 'self' https://*.fontawesome.com;