Improve CSP setup
1 file changed, 1 insertion(+), 1 deletion(-)
jump to
M Caddyfile → Caddyfile
@@ -55,7 +55,7 @@ header { Cache-Control max-age=14400 X-Content-Type-Options nosniff Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" - Content-Security-Policy "default-src 'none'; img-src 'self'; object-src 'none'; script-src 'none'; style-src 'unsafe-inline'" + Content-Security-Policy "default-src 'none'; img-src 'self'; object-src 'none'; script-src 'none'; style-src 'unsafe-inline'; form-action 'none'; base-uri 'self'" } handle_errors { @404 expression `{err.status_code} == 404`