20 lines
No EOL
486 B
Django/Jinja
20 lines
No EOL
486 B
Django/Jinja
directives:
|
|
connect-src:
|
|
- "'self'"
|
|
- "blob:"
|
|
- "https://raw.githubusercontent.com/opencloud-eu/awesome-apps/"
|
|
- "https://update.opencloud.eu/"
|
|
{% for url in opencloud_csp_extra_connect_src %}
|
|
- "{{ url }}"
|
|
{% endfor %}
|
|
{% if opencloud_csp_extra_frame_src | length > 0 %}
|
|
frame-src:
|
|
- "'self'"
|
|
{% for url in opencloud_csp_extra_frame_src %}
|
|
- "{{ url }}"
|
|
{% endfor %}
|
|
{% endif %}
|
|
script-src:
|
|
- "'self'"
|
|
- "'unsafe-inline'"
|
|
- "'unsafe-eval'" |