From: Andreas Gerstenberg <gerstenberg@pixelpark.com>
Date: Thu, 12 Oct 2017 15:35:14 +0000 (+0200)
Subject: spk-spar-checker modify Content-Security-Policy
X-Git-Tag: v0.1.0~2338
X-Git-Url: https://git.uhu-banane.net/?a=commitdiff_plain;h=251fad46dc829f48cd8bc0798b285ebd22f69e93;p=pixelpark%2Fhiera.git

spk-spar-checker modify Content-Security-Policy
---

diff --git a/customer/spk-spar-checker/test.yaml b/customer/spk-spar-checker/test.yaml
index d7212db9..4d14fbf4 100644
--- a/customer/spk-spar-checker/test.yaml
+++ b/customer/spk-spar-checker/test.yaml
@@ -39,7 +39,7 @@ infra::profile::apache::pp_vhosts:
       - 'always set X-Frame-Options "SAMEORIGIN"'
       - 'always set X-Content-Type-Options "nosniff"'
       - 'always set Strict-Transport-Security: "max-age=15768001"'
-#      - 'always set Content-Security-Policy "default-src 'none'; connect-src 'self'; script-src 'self' data: www.google-analytics.com 'sha256-aed8ae7e95bc21fd56a9074f9eedd4db237cf41ebb8ea603d8bf6764f0d23f4c'; style-src 'self' data: https://webfonts.sparkasse.de 'unsafe-inline'; img-src 'self' data: img.vxcdn.com www.google-analytics.com www.verivox.de; font-src 'self' data: https://webfonts.sparkasse.de; child-src 'self'; object-src 'self'; form-action 'self'; report-uri /api/v1/report;"
+      - "always set Content-Security-Policy \"default-src 'none'; connect-src 'self'; script-src 'self' data: www.google-analytics.com 'sha256-aed8ae7e95bc21fd56a9074f9eedd4db237cf41ebb8ea603d8bf6764f0d23f4c'; style-src 'self' data: https://webfonts.sparkasse.de 'unsafe-inline'; img-src 'self' data: img.vxcdn.com www.google-analytics.com www.verivox.de; font-src 'self' data: https://webfonts.sparkasse.de; child-src 'self'; object-src 'self'; form-action 'self'; report-uri /api/v1/report;\""
 
     aliases:
       - { alias: /api , path: /var/www/spar-checker/sparchecker-backend/public/api }