]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
added CSP header on Orat test and PRD
authorsambufe <samuel.bufe@publicispixelpark.de>
Thu, 6 Apr 2017 10:05:39 +0000 (12:05 +0200)
committersambufe <samuel.bufe@publicispixelpark.de>
Thu, 6 Apr 2017 10:05:39 +0000 (12:05 +0200)
customer/fbb-orat/test.yaml

index f8092a5c888a72bd043c648e507edb43b659b67f..7c0e87fa4498313d51fec34476a8b328e3b8078b 100644 (file)
@@ -53,7 +53,7 @@ infra::profile::wordpress::projects:
       - 'set Cache-Control "private, no-cache, no-store, must-revalidate, max-age=0"'
       - 'set Pragma "no-cache"'
       - 'set Expires 0'
-#      - "set Content-Security-Policy: \"default-src 'self' www.youtube.com; img-src 'self' *.fbcdn.net secure.gravatar.com *.google-analytics.com *.facebook.com www.google.com www.youtube.com *.doubleclick.net data:; font-src 'self' fonts.gstatic.com data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.addthis.com *.addthisedge.com *.google-analytics.com *.facebook.com www.google.com www.youtube.com *.doubleclick.net; child-src 'self' *.facebook.com; frame-ancestors 'self';\""
+      - "set Content-Security-Policy: \"default-src 'self' www.youtube.com; img-src 'self' *.fbcdn.net secure.gravatar.com *.google-analytics.com *.facebook.com www.google.com www.youtube.com *.doubleclick.net data:; font-src 'self' fonts.gstatic.com data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.addthis.com *.addthisedge.com *.google-analytics.com *.facebook.com www.google.com www.youtube.com *.doubleclick.net; child-src 'self' *.facebook.com; frame-ancestors 'self';\""
     directories:
       - provider: location
         path: '/wp-admin/'