Experimental switch of parameters and different urls

This commit is contained in:
James Cole
2020-01-09 20:43:32 +01:00
parent 987730b36b
commit 925f63c8e1

View File

@@ -53,13 +53,13 @@ class SecureHeaders
$analyticsId = config('firefly.analytics_id'); $analyticsId = config('firefly.analytics_id');
if ('' !== $analyticsId) { if ('' !== $analyticsId) {
$google = 'www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js'; // @codeCoverageIgnore $google = 'https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js'; // @codeCoverageIgnore
$googleImg = 'https://www.google-analytics.com/'; $googleImg = 'https://www.google-analytics.com/';
} }
$csp = [ $csp = [
"default-src 'none'", "default-src 'none'",
"object-src 'self'", "object-src 'self'",
sprintf("script-src 'nonce-%s' 'unsafe-inline' %s", $nonce, $google), sprintf("script-src 'unsafe-inline' %s 'nonce-%s'", $nonce, $google),
"style-src 'self' 'unsafe-inline'", "style-src 'self' 'unsafe-inline'",
"base-uri 'self'", "base-uri 'self'",
"font-src 'self' data:", "font-src 'self' data:",