From 72d8707c5b83959048c58f40b4baca7d4a11fb0c Mon Sep 17 00:00:00 2001 From: Jason Frey Date: Tue, 23 Apr 2024 15:50:20 -0400 Subject: [PATCH] Sort directives --- config/initializers/secure_headers.rb | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index 15ca44a72bb..63bc18e1e0b 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -15,14 +15,15 @@ # Need google fonts in fonts_src for https://fonts.googleapis.com/css?family=IBM+Plex+Sans+Condensed%7CIBM+Plex+Sans:400,600&display=swap (For carbon-charts download) config.csp = { :report_only => false, + :report_uri => ["/dashboard/csp_report"] + :default_src => ["'self'"], - :frame_src => ["'self'"], + :connect_src => ["'self'"], :font_src => ["'self'", 'https://fonts.gstatic.com', "https://fonts.googleapis.com"], + :frame_src => ["'self'"], :img_src => ["'self'", "data:"], - :connect_src => ["'self'"], - :style_src => ["'unsafe-inline'", "'self'", "https://fonts.googleapis.com", "https://fonts.gstatic.com"], :script_src => ["'unsafe-eval'", "'unsafe-inline'", "'self'"], - :report_uri => ["/dashboard/csp_report"] + :style_src => ["'unsafe-inline'", "'self'", "https://fonts.googleapis.com", "https://fonts.gstatic.com"], } end end