From 868208dd2f1479870c9cb58b723a651d3952bd1f Mon Sep 17 00:00:00 2001 From: Jeff Swartz Date: Wed, 13 Nov 2024 14:39:49 -0800 Subject: [PATCH] Minor refactoring of CSP directives --- server/serverMethods.js | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/server/serverMethods.js b/server/serverMethods.js index 54a28823..aa8c8927 100644 --- a/server/serverMethods.js +++ b/server/serverMethods.js @@ -73,12 +73,18 @@ const securityHeaders = helmet({ 'cdnjs.cloudflare.com', 'assets.tokbox.com', 'www.google-analytics.com', - 'https://unpkg.com/@vonage/client-sdk-video@2/dist/js/opentok.js', + 'https://unpkg.com/@vonage/', 'static.opentok.com', 'www.googletagmanager.com', 'assets.adobedtm.com', ], - styleSrc: ["'self'", "'unsafe-inline'", 'cdnjs.cloudflare.com', 'assets.tokbox.com', 'static.opentok.com'], + styleSrc: [ + "'self'", + "'unsafe-inline'", + 'cdnjs.cloudflare.com', + 'assets.tokbox.com', + 'static.opentok.com', + ], connectSrc: ['*'], imgSrc: ['*', 'data:'], },