diff --git a/server/server.js b/server/server.js index d484f60357..d588f79794 100755 --- a/server/server.js +++ b/server/server.js @@ -127,6 +127,7 @@ var trusted = [ '*.ytimg.com', '*.bitly.com', 'http://cdn.inspectlet.com/', + 'https://cdn.inspeclet.com/', 'wss://inspectletws.herokuapp.com/', 'http://hn.inspectlet.com/', '*.googleapis.com', @@ -138,7 +139,9 @@ app.use(helmet.csp({ scriptSrc: [ '*.optimizely.com', '*.aspnetcdn.com', - '*.d3js.org' + '*.d3js.org', + 'https://cdn.inspectlet.com/inspectlet.js', + 'http://cdn.inspectlet.com/inspectlet.js' ].concat(trusted), 'connect-src': [ ].concat(trusted), diff --git a/server/views/partials/universal-head.jade b/server/views/partials/universal-head.jade index c33c77acaa..47bc657df6 100644 --- a/server/views/partials/universal-head.jade +++ b/server/views/partials/universal-head.jade @@ -70,7 +70,7 @@ script#inspectletjs(type='text/javascript'). insp.type = 'text/javascript'; insp.async = true; insp.id = "inspsync"; - insp.src = ('https:' == document.location.protocol ? 'https' : 'http') + '://cdn.inspectlet.com/inspectlet.js'; + insp.src = '//cdn.inspectlet.com/inspectlet.js'; var x = document.getElementsByTagName('script')[0]; x.parentNode.insertBefore(insp, x); }