diff --git a/frontend/public/_headers b/frontend/public/_headers index cdb13a7..b9bba21 100644 --- a/frontend/public/_headers +++ b/frontend/public/_headers @@ -1,6 +1,6 @@ /* - Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-eval' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com; img-src 'self' https://cdn.discordapp.com https://media.discordapp.net; font-src https://fonts.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com; connect-src https://api.ticketsbot.net wss://api.ticketsbot.net https://cloudflareinsights.com/cdn-cgi/rum; media-src https://cdn.discordapp.com https://media.discordapp.net; frame-src 'self' + Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-eval' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com; img-src 'self' https://cdn.discordapp.com https://media.discordapp.net https://image-cdn.ticketsbot.net; font-src https://fonts.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com; connect-src https://api.ticketsbot.net wss://api.ticketsbot.net https://cloudflareinsights.com/cdn-cgi/rum; media-src https://cdn.discordapp.com https://media.discordapp.net; frame-src 'self' /manage/*/transcripts/view/* ! Content-Security-Policy - Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://cdnjs.cloudflare.com/ajax/libs/highlight.js/; img-src 'self' https://cdn.discordapp.com https://media.discordapp.net; font-src https://fonts.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com; connect-src https://api.ticketsbot.net wss://api.ticketsbot.net https://cloudflareinsights.com/cdn-cgi/rum; media-src https://cdn.discordapp.com https://media.discordapp.net; frame-src 'self' + Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://cdnjs.cloudflare.com/ajax/libs/highlight.js/; img-src 'self' https://cdn.discordapp.com https://media.discordapp.net https://image-cdn.ticketsbot.net; font-src https://fonts.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com; connect-src https://api.ticketsbot.net wss://api.ticketsbot.net https://cloudflareinsights.com/cdn-cgi/rum; media-src https://cdn.discordapp.com https://media.discordapp.net; frame-src 'self'