File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 3232 {{- if .Values.nginx.securityHeaders.enabled }}
3333 add_header X-Content-Type-Options "{{ .Values.nginx.securityHeaders.xContentTypeOptions }}" always;
3434 add_header X-Frame-Options "{{ .Values.nginx.securityHeaders.xFrameOptions }}" always;
35- add_header Content-Security-Policy "{{ .Values.nginx.securityHeaders.contentSecurityPolicy }}" always;
35+ add_header Content-Security-Policy "{{ .Values.nginx.securityHeaders.contentSecurityPolicy }}{{- range .Values.nginx.securityHeaders.extraCspDomains }} {{ . }}{{- end }}; " always;
3636 add_header Permissions-Policy "{{ .Values.nginx.securityHeaders.permissionsPolicy }}" always;
3737 add_header Referrer-Policy "{{ .Values.nginx.securityHeaders.referrerPolicy }}" always;
3838 {{- else }}
Original file line number Diff line number Diff line change @@ -538,7 +538,10 @@ nginx:
538538 securityHeaders :
539539 enabled : true
540540 xContentTypeOptions : " nosniff"
541- contentSecurityPolicy : " default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob:;"
541+ contentSecurityPolicy : " default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://login.openops.com https://assets.frontegg.com https://fonts.cdnfonts.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.github.com https://app.openops.com https://cdn.jsdelivr.net"
542+ # Additional domains to append to the CSP default-src directive
543+ extraCspDomains : []
544+ # - https://example.com
542545 permissionsPolicy : " geolocation=(), microphone=(), camera=()"
543546 referrerPolicy : " strict-origin-when-cross-origin"
544547 # Rate limiting - ENABLED BY DEFAULT for security
You can’t perform that action at this time.
0 commit comments