From 3a02f4fd42f34a0b0e83aedeca83c20aac242319 Mon Sep 17 00:00:00 2001 From: cade Date: Thu, 11 Jul 2024 23:27:14 -0600 Subject: [PATCH] update security headers --- vercel.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/vercel.json b/vercel.json index 6ac8a67f..19edf701 100644 --- a/vercel.json +++ b/vercel.json @@ -7,7 +7,7 @@ "headers": [ { "key": "Content-Security-Policy", - "value": "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;" + "value": "default-src 'self'; connect-src 'self' https://*.supabase.co/auth/v1/user wss://*.supabase.co/realtime/v1/websocket; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests;" }, { "key": "Permissions-Policy",