updated CSP

This commit is contained in:
Eugene Pankov 2022-11-08 10:50:05 +01:00
parent b95b612a0b
commit 6379814a08
No known key found for this signature in database
GPG Key ID: 5896FCBBDD1CF4F4

View File

@ -26,6 +26,7 @@ class TerminalView(APIView):
response = static.serve(
request, "terminal.html", document_root=str(settings.STATIC_ROOT)
)
response["Content-Security-Policy"] = "frame-ancestors 'self' https://tabby.sh;"
response["X-Frame-Options"] = "SAMEORIGIN"
return response
@ -35,7 +36,8 @@ class DemoView(APIView):
response = static.serve(
request, "demo.html", document_root=str(settings.STATIC_ROOT)
)
response["Content-Security-Policy"] = "frame-ancestors https://tabby.sh"
response["Content-Security-Policy"] = "frame-ancestors 'self' https://tabby.sh;"
response['X-Frame-Options'] = 'ALLOW-FROM https://tabby.sh'
return response