refactor: disable Content Security Policy in security middleware to allow HTTP access

This commit is contained in:
Tudor Stanciu 2025-10-04 03:11:01 +03:00
parent e309e4f71b
commit 9dddf2fa29

View File

@ -21,19 +21,7 @@ const app = express();
// Security middleware
app.use(
helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'", 'https://unpkg.com'],
scriptSrc: ["'self'"],
imgSrc: ["'self'", 'data:', 'https:'],
connectSrc: ["'self'"],
fontSrc: ["'self'"],
objectSrc: ["'none'"],
mediaSrc: ["'self'"],
frameSrc: ["'none'"],
},
},
contentSecurityPolicy: false, // Disable CSP to allow HTTP access
strictTransportSecurity: false, // Disable HSTS to allow HTTP access
crossOriginOpenerPolicy: false, // Disable COOP to allow HTTP access
crossOriginResourcePolicy: false, // Disable CORP to allow HTTP access