Skip to content

Commit ca1c150

Browse files
add csp headers
1 parent 3f18d6a commit ca1c150

File tree

5 files changed

+5
-0
lines changed

5 files changed

+5
-0
lines changed

web-assets/local/index.html

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<head>
55
<title>Auth0</title>
66
<meta charset="utf-8" />
7+
<meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline'; font-src * 'unsafe-inline'; frame-ancestors * data: blob:;">
78
<script language="javascript" type="text/javascript"
89
src="https://accounts-auth0.topcoder-dev.com/setupAuth0WithRedirect.js"></script>
910
</head>

web-assets/static-pages/check_email.html

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66
<meta charset="utf-8" />
77
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
88
<meta name="viewport" content="width=device-width, initial-scale=1" />
9+
<meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline'; font-src * 'unsafe-inline'; frame-ancestors * data: blob:;">
910
<link rel="shortcut icon" href="./images/favicon.ico" />
1011
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@100;300;400;500;700&display=swap" rel="stylesheet" />
1112
<link href="https://fonts.googleapis.com/css2?family=Barlow&family=Barlow+Condensed:wght@500&display=swap"

web-assets/static-pages/index.html

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<title>Auth0</title>
55
<meta charset="utf-8" />
66
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
7+
<meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline'; font-src * 'unsafe-inline'; frame-ancestors * data: blob:;">
78
<meta name="viewport" content="width=device-width, initial-scale=1" />
89
<link rel="shortcut icon" href="./images/favicon.ico" />
910
<script src="./setupAuth0WithRedirect.js"></script>

web-assets/static-pages/register_success.html

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<title>Register Success</title>
55
<meta charset="utf-8" />
66
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
7+
<meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline'; font-src * 'unsafe-inline'; frame-ancestors * data: blob:;">
78
<meta name="viewport" content="width=device-width, initial-scale=1" />
89
<link rel="shortcut icon" href="./images/favicon.ico" />
910
<link

web-assets/static-pages/signup.html

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<title>Signup</title>
55
<meta charset="utf-8" />
66
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
7+
<meta http-equiv="Content-Security-Policy" content="default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob:; frame-src *; style-src * 'unsafe-inline'; font-src * 'unsafe-inline'; frame-ancestors * data: blob:;">
78
<meta name="viewport" content="width=device-width, initial-scale=1" />
89
<link rel="shortcut icon" href="./images/favicon.ico" />
910
<link

0 commit comments

Comments
 (0)