diff --git a/apps/core/middleware.py b/apps/core/middleware.py index a04983f..0152ed1 100644 --- a/apps/core/middleware.py +++ b/apps/core/middleware.py @@ -25,9 +25,9 @@ class SecurityHeadersMiddleware: response["Content-Security-Policy"] = ( f"default-src 'self'; " f"script-src 'self' 'nonce-{nonce}'; " - "style-src 'self'; " + "style-src 'self' https://fonts.googleapis.com; " "img-src 'self' data: blob:; " - "font-src 'self'; " + "font-src 'self' https://fonts.gstatic.com; " "connect-src 'self'; " "object-src 'none'; " "base-uri 'self'; "