Skip to content

Commit

Permalink
fix: beef up CSP headers (#1759)
Browse files Browse the repository at this point in the history
* fix: beef up CSP headers

* add base-uri self

* fix connect-src for tesseract

* more csp fixes
  • Loading branch information
nolanlawson authored May 3, 2020
1 parent 00b9b1c commit 6447326
Showing 1 changed file with 21 additions and 4 deletions.
25 changes: 21 additions & 4 deletions bin/build-now-json.js
Original file line number Diff line number Diff line change
Expand Up @@ -55,16 +55,33 @@ const JSON_TEMPLATE = {
]
}

const SCRIPT_CHECKSUMS = [inlineScriptChecksum]
.concat(sapperInlineScriptChecksums)
.map(_ => `'sha256-${_}'`)
.join(' ')

const HTML_HEADERS = {
'cache-control': 'public,max-age=3600',
'content-security-policy': 'script-src \'self\' ' +
`${[inlineScriptChecksum].concat(sapperInlineScriptChecksums).map(_ => `'sha256-${_}'`).join(' ')}; ` +
'worker-src \'self\'; style-src \'self\' \'unsafe-inline\'; frame-src \'none\'; object-src \'none\'; manifest-src \'self\'',
'content-security-policy': [
"default-src 'self'",
`script-src 'self' ${SCRIPT_CHECKSUMS}`,
"worker-src 'self'",
"style-src 'self' 'unsafe-inline'",
"img-src 'self' * data: blob:",
"media-src 'self' *",
"connect-src 'self' * data: blob:",
"frame-src 'none'",
"frame-ancestors 'none'",
"object-src 'none'",
"manifest-src 'self'",
"form-action 'none'",
"base-uri 'self'"
].join(';'),
'referrer-policy': 'no-referrer',
'strict-transport-security': 'max-age=15552000; includeSubDomains',
'x-content-type-options': 'nosniff',
'x-download-options': 'noopen',
'x-frame-options': 'SAMEORIGIN',
'x-frame-options': 'DENY',
'x-xss-protection': '1; mode=block'
}

Expand Down

0 comments on commit 6447326

Please sign in to comment.