From 7b106ae15d183a97dc6d71e87faee0acc0dc685e Mon Sep 17 00:00:00 2001 From: Matheus Cristian Date: Tue, 7 May 2024 11:54:23 -0300 Subject: [PATCH] feat(csp-settings): adds sienge domain in CSP --- nginx.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nginx.conf b/nginx.conf index e199918f..9cd661b0 100644 --- a/nginx.conf +++ b/nginx.conf @@ -30,7 +30,7 @@ http { set $CSP_STYLE "style-src 'self' 'unsafe-hashes' 'unsafe-inline' fonts.googleapis.com"; set $CSP_FONT "font-src 'self' fonts.gstatic.com"; set $CSP_IMAGE "img-src 'self' data: www.google.com.br www.googletagmanager.com *.amazonaws.com"; - set $CSP_CHILD "child-src 'self' *.weni.ai m.stripe.network js.stripe.com *.amazonaws.com"; + set $CSP_CHILD "child-src 'self' *.weni.ai m.stripe.network js.stripe.com *.amazonaws.com *.doubleclick.net *.sienge.com.br"; set $CSP_CONNECT "connect-src 'self' *.weni.ai www.google-analytics.com analytics.google.com"; add_header Content-Security-Policy "${CSP_DEFAULT}; ${CSP_SCRIPT}; ${CSP_STYLE}; ${CSP_FONT}; ${CSP_IMAGE}; ${CSP_CHILD}; ${CSP_CONNECT};";