Update CSP to remove vimeo and add youtube

This commit is contained in:
Quincy Larson
2016-04-19 00:23:27 -07:00
parent 6f9b6d7f2b
commit f1b5bffdd8

View File

@ -26,10 +26,6 @@ export default function csp() {
'*.jsdelivr.com', '*.jsdelivr.com',
'*.twimg.com', '*.twimg.com',
'https://*.twimg.com', 'https://*.twimg.com',
'vimeo.com'
].concat(trusted),
connectSrc: [
'vimeo.com'
].concat(trusted), ].concat(trusted),
styleSrc: [ styleSrc: [
"'unsafe-inline'", "'unsafe-inline'",
@ -62,7 +58,7 @@ export default function csp() {
frameSrc: [ frameSrc: [
'*.gitter.im', '*.gitter.im',
'*.gitter.im https:', '*.gitter.im https:',
'*.vimeo.com', '*.youtube.com',
'*.twitter.com', '*.twitter.com',
'*.ghbtns.com', '*.ghbtns.com',
'*.freecatphotoapp.com', '*.freecatphotoapp.com',