Skip to content

Commit

Permalink
add basic content-security-policy for preset themes.
Browse files Browse the repository at this point in the history
  • Loading branch information
mbien committed Jun 22, 2023
1 parent 5c94c25 commit a8a46a1
Show file tree
Hide file tree
Showing 5 changed files with 5 additions and 0 deletions.
1 change: 1 addition & 0 deletions app/src/main/webapp/themes/basic/weblog.vm
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'none'">
<title>$model.weblog.name</title>
#showAutodiscoveryLinks($model.weblog)
#showAnalyticsTrackingCode($model.weblog)
Expand Down
1 change: 1 addition & 0 deletions app/src/main/webapp/themes/basicmobile/weblog.vm
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'none'">
<title>$model.weblog.name</title>
#showAutodiscoveryLinks($model.weblog)
#showAnalyticsTrackingCode($model.weblog)
Expand Down
1 change: 1 addition & 0 deletions app/src/main/webapp/themes/fauxcoly/weblog.vm
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'none'">
#includeTemplate($model.weblog "standard_head")
<title>$model.weblog.name: $model.weblog.tagline</title>
#showAutodiscoveryLinks($model.weblog)
Expand Down
1 change: 1 addition & 0 deletions app/src/main/webapp/themes/frontpage/_header.vm
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'none'">
<title>$model.weblog.name</title>
<link href="$url.absoluteSite/favicon.ico" rel="shortcut icon" type="image/x-icon" />
#showAutodiscoveryLinks($model.weblog)
Expand Down
1 change: 1 addition & 0 deletions app/src/main/webapp/themes/gaurav/std_head.vm
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src *; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'none'">
#if ($model.permalink == false)
<meta name="Description" content="$model.weblog.about">
#else
Expand Down

0 comments on commit a8a46a1

Please sign in to comment.