Merge branch 'dev' of https://github.com/umami-software/umami into dev
Some checks are pending
Create docker images / Build, push, and deploy (push) Waiting to run
Node.js CI / build (postgresql, 18.18, 10) (push) Waiting to run

This commit is contained in:
Francis Cao 2025-10-01 12:29:41 -07:00
commit ec81cd665f

View file

@ -14,14 +14,14 @@ const frameAncestors = process.env.ALLOWED_FRAME_URLS || '';
const trackerScriptName = process.env.TRACKER_SCRIPT_NAME || ''; const trackerScriptName = process.env.TRACKER_SCRIPT_NAME || '';
const trackerScriptURL = process.env.TRACKER_SCRIPT_URL || ''; const trackerScriptURL = process.env.TRACKER_SCRIPT_URL || '';
const contentSecurityPolicy = [ const contentSecurityPolicy = `
`default-src 'self'`, default-src 'self';
`img-src * data:`, img-src 'self' https: data:;
`script-src 'self' 'unsafe-eval' 'unsafe-inline'`, script-src 'self' 'unsafe-eval' 'unsafe-inline';
`style-src 'self' 'unsafe-inline'`, style-src 'self' 'unsafe-inline';
`connect-src 'self' api.umami.is cloud.umami.is`, connect-src *;
`frame-ancestors 'self' ${frameAncestors}`, frame-ancestors 'self' ${frameAncestors};
]; `;
const defaultHeaders = [ const defaultHeaders = [
{ {
@ -30,10 +30,7 @@ const defaultHeaders = [
}, },
{ {
key: 'Content-Security-Policy', key: 'Content-Security-Policy',
value: contentSecurityPolicy value: contentSecurityPolicy.replace(/\s{2,}/g, ' ').trim(),
.join(';')
.replace(/\s{2,}/g, ' ')
.trim(),
}, },
]; ];