From afa8f6e2d6a46dfd633a785ec48ef386728937a2 Mon Sep 17 00:00:00 2001 From: Daniel Kraus Date: Sat, 10 Sep 2016 09:46:58 +0200 Subject: [PATCH] Add code.jquery.com to CSP header. --- .htaccess | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.htaccess b/.htaccess index 7eb6cc6..0502ad2 100644 --- a/.htaccess +++ b/.htaccess @@ -1,4 +1,4 @@ -Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com; style-src 'self'" +Header set Content-Security-Policy "default-src *; script-src 'self' ajax.googleapis.com code.jquery.com; style-src 'self'" Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" # Header set X-Frame-Options "sameorigin" Header set X-XSS-Protection "1; mode=block"