Allow iframe embedding of cloudron.io pages
This commit is contained in:
+1
-1
@@ -96,7 +96,7 @@ server {
|
|||||||
|
|
||||||
<% if ( endpoint === 'admin' ) { -%>
|
<% if ( endpoint === 'admin' ) { -%>
|
||||||
# CSP headers for the admin/dashboard resources
|
# CSP headers for the admin/dashboard resources
|
||||||
add_header Content-Security-Policy "default-src 'none'; connect-src wss: https: 'self' *.cloudron.io; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; style-src https: 'unsafe-inline'; object-src 'none'; font-src https: 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'self';";
|
add_header Content-Security-Policy "default-src 'none'; frame-src cloudron.io *.cloudron.io; connect-src wss: https: 'self' *.cloudron.io; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; style-src https: 'unsafe-inline'; object-src 'none'; font-src https: 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'self';";
|
||||||
<% } -%>
|
<% } -%>
|
||||||
|
|
||||||
proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
|
|||||||
Reference in New Issue
Block a user