|
|
@@ -82,7 +82,12 @@ stylesrc = [
|
|
|
"https://fonts.googleapis.com/",
|
|
|
"https://cdn.jsdelivr.net/"
|
|
|
]
|
|
|
-scriptsrc = ["'self'", "'unsafe-inline'", "https://www.google-analytics.com"]
|
|
|
+scriptsrc = [
|
|
|
+ "'self'",
|
|
|
+ "'unsafe-inline'",
|
|
|
+ "https://www.google-analytics.com",
|
|
|
+ "https://cdn.jsdelivr.net/"
|
|
|
+]
|
|
|
prefetchsrc = ["'self'"]
|
|
|
# connect-src directive – defines valid targets for to XMLHttpRequest (AJAX), WebSockets or EventSource
|
|
|
connectsrc = ["'self'", "https://www.google-analytics.com"]
|