diff --git a/src/middleware/csp.ts b/src/middleware/csp.ts index 6f5c3a8..f97fc9a 100644 --- a/src/middleware/csp.ts +++ b/src/middleware/csp.ts @@ -8,17 +8,17 @@ const csp = (): AppMiddleware => { const policies = [ 'upgrade-insecure-requests', - 'script-src \'self\'', + `script-src 'self'`, `connect-src 'self' blob: ${Conf.localDomain} ${wsProtocol}//${host}`, `media-src 'self' ${Conf.mediaDomain}`, `img-src 'self' data: blob: ${Conf.mediaDomain}`, - 'default-src \'none\'', - 'base-uri \'self\'', - 'frame-ancestors \'none\'', - 'style-src \'self\' \'unsafe-inline\'', - 'font-src \'self\'', - 'manifest-src \'self\'', - 'frame-src \'self\' https:', + `default-src 'none'`, + `base-uri 'self'`, + `frame-ancestors 'none'`, + `style-src 'self' 'unsafe-inline'`, + `font-src 'self'`, + `manifest-src 'self'`, + `frame-src 'self' https:`, ]; c.res.headers.set('content-security-policy', policies.join('; '));