Skip to content

Instantly share code, notes, and snippets.

@johanbove
Created May 23, 2019 09:01
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save johanbove/92de89a35668ef40f5044cceb5a483af to your computer and use it in GitHub Desktop.
Save johanbove/92de89a35668ef40f5044cceb5a483af to your computer and use it in GitHub Desktop.
Content-security-policy for my Known site including Twitter domains
# Content-Security-Policy (CSP)
<IfModule mod_headers.c>
Header set Content-Security-Policy: "default-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.brid.gy https://indieauth.com/ https://monocle.p3k.io/ https://aperture.p3k.io https://syndication.twitter.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://publish.twitter.com https://platform.twitter.com https://cdn.syndication.twimg.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://platform.twitter.com; img-src https:; media-src *; worker-src 'self' https; font-src *; connect-src 'self' https://publish.twitter.com; frame-src 'self' https://platform.twitter.com https://syndication.twitter.com/; script-src-elem 'self' https://cdn.syndication.twimg.com"
Header set X-Content-Security-Policy: "default-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.brid.gy https://indieauth.com/ https://monocle.p3k.io/ https://aperture.p3k.io https://syndication.twitter.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://publish.twitter.com https://platform.twitter.com https://cdn.syndication.twimg.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://platform.twitter.com; img-src https:; media-src *; worker-src 'self' https; font-src *; connect-src 'self' https://publish.twitter.com; frame-src 'self' https://platform.twitter.com https://syndication.twitter.com/; script-src-elem 'self' https://cdn.syndication.twimg.com"
Header set X-WebKit-CSP: "default-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.brid.gy https://indieauth.com/ https://monocle.p3k.io/ https://aperture.p3k.io https://syndication.twitter.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://publish.twitter.com https://platform.twitter.com https://cdn.syndication.twimg.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://platform.twitter.com; img-src *; media-src https:; worker-src 'self' https; font-src *; connect-src 'self' https://publish.twitter.com; frame-src 'self' https://platform.twitter.com https://syndication.twitter.com/; script-src-elem 'self' https://cdn.syndication.twimg.com"
</IfModule>
# ... continues
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment