From c320b95be982b51497201dbd260263b555ebf50e Mon Sep 17 00:00:00 2001 From: Evan Rusackas Date: Tue, 27 Feb 2024 15:53:00 -0700 Subject: [PATCH] fix(docs): even more CSP adjustments... (#27278) --- docs/static/.htaccess | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/static/.htaccess b/docs/static/.htaccess index aa0c75e328..5453e5eb80 100644 --- a/docs/static/.htaccess +++ b/docs/static/.htaccess @@ -22,7 +22,7 @@ RewriteRule ^(.*)$ https://superset.apache.org/$1 [R,L] RewriteCond %{HTTP_HOST} ^superset.incubator.apache.org$ [NC] RewriteRule ^(.*)$ https://superset.apache.org/$1 [R=301,L] -Header set Content-Security-Policy "default-src 'self'; img-src *;" +# Header set Content-Security-Policy "default-src 'self'; img-src *;" Header set Content-Security-Policy "default-src 'self'; \ script-src 'self'; \ @@ -30,6 +30,7 @@ img-src 'self' https://static.scarf.sh *; \ style-src 'self' https://fonts.googleapis.com; \ script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com; \ style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://analytics.apache.org https://www.bugherd.com; \ +frame-ancestors 'self' https://preset.io; \ font-src 'self' https://fonts.gstatic.com; \ frame-src 'self' https://calendar.google.com https://preset.io https://sidebar.bugherd.com https://unpkg.com; \ "