another attempt at fixing

This commit is contained in:
Michael Q Larson
2014-12-22 15:54:43 -08:00
parent d8158041de
commit ae9c61fc64

2
app.js
View File

@ -121,7 +121,7 @@ app.use(helmet.contentSecurityPolicy({
defaultSrc: trusted, defaultSrc: trusted,
scriptSrc: ['*.optimizely.com'].concat(trusted), scriptSrc: ['*.optimizely.com'].concat(trusted),
'connect-src': process.env.NODE_ENV === 'development' ? ['ws://localhost:3001/', 'http://localhost:3001/'] : [], 'connect-src': process.env.NODE_ENV === 'development' ? ['ws://localhost:3001/', 'http://localhost:3001/'] : [],
connectSources: ["ws://api.rafflecopter.com", "wss://api.rafflecopter.com", "ws://www.freecodecamp.com"], connectSources: ["ws://api.rafflecopter.com", "wss://api.rafflecopter.com", "ws://www.freecodecamp.com"].concat(trusted),
styleSrc: trusted, styleSrc: trusted,
imgSrc: ['*.evernote.com', '*.amazonaws.com', "data:", '*.licdn.com'].concat(trusted), imgSrc: ['*.evernote.com', '*.amazonaws.com', "data:", '*.licdn.com'].concat(trusted),
fontSrc: ["'self", '*.googleapis.com'].concat(trusted), fontSrc: ["'self", '*.googleapis.com'].concat(trusted),