Browse Source

img-src 'self' data: https://*.amazonaws.com;

master
review512jwy@163.com 5 days ago
parent
commit
80559dffd1
  1. 2
      dongjian-dashboard-back-controller/src/main/java/com/dongjian/dashboard/back/configurator/CrosXssFilter.java

2
dongjian-dashboard-back-controller/src/main/java/com/dongjian/dashboard/back/configurator/CrosXssFilter.java

@ -79,7 +79,7 @@ public class CrosXssFilter implements Filter {
String nonce = UUID.randomUUID().toString().replace("-", "").substring(0, 16); // 生成随机 nonce
httpServletResponse.setHeader("Content-Security-Policy",
"default-src 'self'; " +
"img-src 'self' data:; "+
"img-src 'self' data: https://*.amazonaws.com;"+
"font-src 'self' https://i.alicdn.com data:; "+ //阿里系的ui组件
// "script-src 'self' 'nonce-" + nonce + "'; " + //nonce针对内联 JavaScript
// "style-src 'self' 'nonce-" + nonce + "'; " + //nonce针对内联 CSS

Loading…
Cancel
Save