diff --git a/netlify.toml b/netlify.toml index f864296..7f7a95b 100644 --- a/netlify.toml +++ b/netlify.toml @@ -9,7 +9,7 @@ # Activates the browser's built-in cross-site scripting (XSS) filter and blocks responses if an attack is detected. X-XSS-Protection = "1; mode=block" # Ensures that only trusted content is executed and styled. - Content-Security-Policy = "default-src 'self'; script-src 'self' 'unsafe-inline' https://cardano.org https://new-cardano-org-staging.netlify.app https://www.googletagmanager.com https://js.hsforms.net https://forms.hsforms.com https://www.google.com https://www.gstatic.com; img-src 'self' https://cardano.org https://new-cardano-org-staging.netlify.app https://forms-eu1.hsforms.com https://forms.hsforms.com data: https://*.ytimg.com; style-src 'self' 'unsafe-inline'; frame-src 'self' https://www.youtube.com https://www.google.com; media-src 'self' https://www.youtube.com; connect-src 'self' https://hubspot-forms-static-embed.s3.amazonaws.com https://forms.hsforms.com https://forms-eu1.hsforms.com" + Content-Security-Policy = "default-src 'self'; script-src 'self' 'unsafe-inline' https://cardano.org https://new-cardano-org-staging.netlify.app https://www.googletagmanager.com https://js.hsforms.net https://forms.hsforms.com https://www.google.com; img-src 'self' https://cardano.org https://new-cardano-org-staging.netlify.app data: https://*.ytimg.com; style-src 'self' 'unsafe-inline'; frame-src 'self' https://www.youtube.com https://www.google.com https://forms-eu1.hsforms.com; media-src 'self' https://www.youtube.com; connect-src 'self' https://hubspot-forms-static-embed.s3.amazonaws.com https://forms.hsforms.com https://forms-eu1.hsforms.com" # Enforces secure connections via HTTPS, protecting against certain types of man-in-the-middle attacks. Strict-Transport-Security = "max-age=63072000; includeSubDomains; preload" # Controls information provided as the HTTP Referer header when navigating from your site, enhancing privacy and security.