diff --git a/nginx.conf b/nginx.conf index 7b23bb8..a7f3e79 100644 --- a/nginx.conf +++ b/nginx.conf @@ -43,7 +43,7 @@ http { add_header X-XSS-Protection "1; mode=block" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "no-referrer-when-downgrade" always; - add_header Content-Security-Policy "default-src 'self' http: https: data: blob:; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:" always; + add_header Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline'" always; # Static assets caching - works for any subfolder or root location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2)$ {