diff --git a/src/nginxconfig.ejs b/src/nginxconfig.ejs index a43a6290a..2c64c90cb 100644 --- a/src/nginxconfig.ejs +++ b/src/nginxconfig.ejs @@ -99,7 +99,7 @@ server { add_header Content-Security-Policy "default-src 'none'; frame-src 'self' cloudron.io *.cloudron.io; connect-src wss: https: 'self' *.cloudron.io; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; img-src * data:; style-src https: 'unsafe-inline'; object-src 'none'; font-src https: 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'self';"; <% } else { %> <% if (frameAncestorsQuoted) { %> - add_header Content-Security-Policy "Frame-ancestors <%= frameAncestorsQuoted %>"; + add_header Content-Security-Policy "Frame-ancestors <%- frameAncestorsQuoted %>"; <% } else { %> add_header Content-Security-Policy "Frame-ancestors 'self'"; <% } %>