We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 1f54414 commit dd09a68Copy full SHA for dd09a68
1 file changed
server/Security/DefaultSecurityHeadersDefinitions.cs
@@ -34,14 +34,20 @@ public static HeaderPolicyCollection GetHeaderPolicyCollection(bool isDev, strin
34
35
if (isDev)
36
{
37
- builder.AddStyleSrc().Self().UnsafeInline();
+ builder.AddStyleSrc()
38
+ .Self()
39
+ .UnsafeInline();
40
}
41
else
42
- builder.AddStyleSrc().WithNonce().UnsafeInline();
43
44
+ .WithNonce()
45
46
47
- builder.AddScriptSrc().WithNonce().UnsafeInline();
48
+ builder.AddScriptSrc()
49
50
+ .UnsafeInline(); // for browser backward compatibility
51
})
52
.RemoveServerHeader()
53
.AddPermissionsPolicyWithDefaultSecureDirectives();
0 commit comments