fix: extend csp to allow datacite and zammad (#48)

This commit is contained in:
rekt-hard
2021-03-09 09:04:24 +01:00
committed by GitHub
parent 92cfad940f
commit 49b5477ebc

View File

@@ -39,7 +39,7 @@ APP_ALLOWED_HOSTS = [
"127.0.0.1", "127.0.0.1",
"invenio-dev01.tugraz.at", "invenio-dev01.tugraz.at",
"invenio-test.tugraz.at", "invenio-test.tugraz.at",
"repository.tugraz.at" "repository.tugraz.at",
] ]
"""Allowed Hosts""" """Allowed Hosts"""
@@ -53,6 +53,9 @@ APP_DEFAULT_SECURE_HEADERS = {
"'unsafe-inline'", "'unsafe-inline'",
"'unsafe-eval'", "'unsafe-eval'",
"blob:", "blob:",
"ub-support.tugraz.at", # zammad contact form
"api.datacite.org/dois", # datacite
"api.test.datacite.org/dois", # datacite test
], ],
}, },
"content_security_policy_report_only": False, "content_security_policy_report_only": False,