diff --git a/nginx_snippets/sv2.conf b/nginx_snippets/sv2.conf index db79cb8806b88ac66a94962d40152a916f0f09db..9add2622dc727d028d0c880c2b98bcc70fe1515a 100644 --- a/nginx_snippets/sv2.conf +++ b/nginx_snippets/sv2.conf @@ -2,7 +2,7 @@ location ~ /.* { root /opt/strudel2/spa/sv2/; #alias /var/www/sv2/dist/sv2/; try_files $uri$args $uri$args/ $uri/ /index.html; - add_header Content-Security-Policy "default-src 'self' *.cloud.cvl.org.au; style-src 'self' fonts.googleapis.com 'unsafe-inline'; font-src 'self' fonts.gstatic.com"; + add_header Content-Security-Policy "default-src 'self' *.cloud.cvl.org.au *.desktop.massive.org.au; style-src 'self' fonts.googleapis.com 'unsafe-inline'; font-src 'self' fonts.gstatic.com"; add_header Strict-Transport-Security "max-age=15768000; includeSubDomains" always; add_header X-Frame-Options "SAMEORIGIN"; add_header X-XSS-Protection "1; mode=block";