diff --git a/public/.htaccess b/public/.htaccess index 1e51da7..52dc021 100644 --- a/public/.htaccess +++ b/public/.htaccess @@ -35,6 +35,9 @@ Header set X-Content-Type-Options "nosniff" # Block site from being framed Header set X-Frame-Options "DENY" +# Content Security Policy generated by Mozilla's CSP Toolkit +Header set Content-Security-Policy "default-src 'none'; img-src 'self' https://p.typekit.net; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://api.github.com https://gist.github.com https://use.typekit.net; style-src 'unsafe-inline' https://assets-cdn.github.com https://netdna.bootstrapcdn.com" + ################ ### Rewrites ### ################