Explicitly add google font servers to whitelist

This commit is contained in:
terakilobyte
2015-06-16 09:33:34 -04:00
parent a621ff3190
commit 7f311a1e03

View File

@ -149,13 +149,15 @@ app.use(helmet.csp({
/* allow all input since we have user submitted images for public profile*/ /* allow all input since we have user submitted images for public profile*/
'*' '*'
].concat(trusted), ].concat(trusted),
fontSrc: ['*.googleapis.com'].concat(trusted), fontSrc: [
'*.googleapis.com',
'*.gstatic.com'
].concat(trusted),
mediaSrc: [ mediaSrc: [
'*.amazonaws.com', '*.amazonaws.com',
'*.twitter.com' '*.twitter.com'
].concat(trusted), ].concat(trusted),
frameSrc: [ frameSrc: [
'*.gitter.im', '*.gitter.im',
'*.gitter.im https:', '*.gitter.im https:',
'*.vimeo.com', '*.vimeo.com',