From 3132937c70b0aac0f3d42008c23d5502c57b6aa2 Mon Sep 17 00:00:00 2001 From: Sawyer Borror <157638613+sawyerb-ksu@users.noreply.github.com> Date: Wed, 7 Aug 2024 12:49:10 -0500 Subject: [PATCH] Update app.yml allowing multi--line csp directives --- config/app.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/app.yml b/config/app.yml index 5aaaddb408..e970e2f616 100644 --- a/config/app.yml +++ b/config/app.yml @@ -67,7 +67,7 @@ all: # 'Content-Security-Policy-Report-Only' or 'Content-Security-Policy' response_header: Content-Security-Policy-Report-Only # Configure CSP response directives. - directives: | + directives: > default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:;