fix: allow Google Fonts in CSP
style-src and font-src were 'self' only, blocking fonts.googleapis.com stylesheet and fonts.gstatic.com font files. Add both origins so Space Grotesk, Inter and Fira Code load correctly in production. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -25,9 +25,9 @@ class SecurityHeadersMiddleware:
|
||||
response["Content-Security-Policy"] = (
|
||||
f"default-src 'self'; "
|
||||
f"script-src 'self' 'nonce-{nonce}'; "
|
||||
"style-src 'self'; "
|
||||
"style-src 'self' https://fonts.googleapis.com; "
|
||||
"img-src 'self' data: blob:; "
|
||||
"font-src 'self'; "
|
||||
"font-src 'self' https://fonts.gstatic.com; "
|
||||
"connect-src 'self'; "
|
||||
"object-src 'none'; "
|
||||
"base-uri 'self'; "
|
||||
|
||||
Reference in New Issue
Block a user