From d3a01e13b567654104a79cff6947be34b47ce71b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fran=C3=A7ois=20Beaufort?= Date: Wed, 8 Sep 2021 10:06:18 +0200 Subject: [PATCH 1/3] Add simple CSP --- firebase.json | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/firebase.json b/firebase.json index a570099..7e1ec41 100644 --- a/firebase.json +++ b/firebase.json @@ -1,5 +1,14 @@ { "hosting": { + "headers": [{ + "source":"**", + "headers": [ + { + "key":"Content-Security-Policy", + "value": "script-src 'self'; object-src 'none'; base-uri 'none'" + } + ] + }], "public": "public", "rewrites": [{ "source": "**", From 09f2eee85b2f47c38e03aca7753770da68e5fd1b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fran=C3=A7ois=20Beaufort?= Date: Fri, 17 Sep 2021 09:47:47 +0200 Subject: [PATCH 2/3] Update firebase.json Co-authored-by: Derek Herman --- firebase.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/firebase.json b/firebase.json index 7e1ec41..e1a7ef6 100644 --- a/firebase.json +++ b/firebase.json @@ -4,7 +4,7 @@ "source":"**", "headers": [ { - "key":"Content-Security-Policy", + "key": "Content-Security-Policy", "value": "script-src 'self'; object-src 'none'; base-uri 'none'" } ] From 1e74310bf29c4136cc892f011afed40ec3edfed9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fran=C3=A7ois=20Beaufort?= Date: Fri, 17 Sep 2021 09:51:12 +0200 Subject: [PATCH 3/3] Update firebase.json --- firebase.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/firebase.json b/firebase.json index e1a7ef6..a205de6 100644 --- a/firebase.json +++ b/firebase.json @@ -1,7 +1,7 @@ { "hosting": { "headers": [{ - "source":"**", + "source": "**", "headers": [ { "key": "Content-Security-Policy",