diff --git a/next.config.mjs b/next.config.mjs index 1cbcff98..720385c0 100644 --- a/next.config.mjs +++ b/next.config.mjs @@ -9,9 +9,11 @@ const nextConfig = { ], }, async headers() { + + /* const cspHeader = ` default-src 'self'; - script-src 'self' 'unsafe-eval'; + script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://cdn.sanity.io; font-src 'self'; @@ -21,6 +23,24 @@ const nextConfig = { frame-ancestors 'none'; upgrade-insecure-requests; `.replace(/\s{2,}/g, ' ').trim(); + */ + + +const cspHeader = ` + default-src 'self'; +script-src 'report-sample' 'self'; +style-src 'report-sample' 'self'; +object-src 'none'; +base-uri 'self'; +connect-src 'self'; +font-src 'self'; +frame-src 'self'; +img-src 'self'; +manifest-src 'self'; +media-src 'self'; +report-uri https://669ece24abce8c3d2411fdd1.endpoint.csper.io/?v=0; +worker-src 'none'; + `.replace(/\s{2,}/g, ' ').trim(); return [ {