chiark / gitweb /
Set a content security policy in .htaccess
authorBen Harris <bjh21@bjh21.me.uk>
Sun, 5 Oct 2025 09:08:46 +0000 (10:08 +0100)
committerBen Harris <bjh21@bjh21.me.uk>
Tue, 13 Jan 2026 21:42:18 +0000 (21:42 +0000)
My Web site disables JavaScript by default, so we need to override
that if the Web editor is going to work.

.htaccess

index fa1c09fc82353ef208bef3718998f4f6ebf879f5..c1bbf5592ba11f3766bb62eaf7f94a88771bd735 100644 (file)
--- a/.htaccess
+++ b/.htaccess
@@ -6,3 +6,4 @@ AddType font/otf;outlines=CFF .otf
 </FilesMatch>
 AddOutputFilterByType DEFLATE application/xhtml+xml text/css font/otf \
  text/plain text/x-csrc application/postscript
+Header set Content-Security-Policy "object-src 'none';"