From 2ae4d87b4df4816478177e20bf23e62af38e9869 Mon Sep 17 00:00:00 2001 From: vchikalkin Date: Sat, 27 Apr 2024 13:48:32 +0300 Subject: [PATCH] Revert "next.config.js: add csp header" This reverts commit 1797c13718e88ce7c30f3b85eb79a6c3d12552db. --- apps/web/next.config.js | 30 ------------------------------ 1 file changed, 30 deletions(-) diff --git a/apps/web/next.config.js b/apps/web/next.config.js index 6c6b413..ca3cbdc 100644 --- a/apps/web/next.config.js +++ b/apps/web/next.config.js @@ -18,38 +18,8 @@ function buildFaviconRewrite(source) { }; } -const cspHeader = ` - upgrade-insecure-requests; - default-src ${ - process.env.NODE_ENV === 'development' ? 'http: ws:' : '' - } https: wss: data: blob: 'self'; - base-uri 'self'; - connect-src 'self' *.evoleasing.ru ${process.env.NODE_ENV === 'development' ? 'ws:' : ''} wss:; - worker-src 'self' blob:; - font-src 'self' fonts.gstatic.com fonts.googleapis.com; - script-src 'self' ${ - process.env.NODE_ENV === 'development' ? "'unsafe-eval' 'unsafe-inline'" : '' - }; - style-src 'self' 'unsafe-inline' fonts.googleapis.com; - object-src 'none'; - frame-ancestors 'none'; -`; - module.exports = withSentryConfig( { - async headers() { - return [ - { - source: '/(.*)', - headers: [ - { - key: 'Content-Security-Policy', - value: cspHeader.replace(/\n/g, ''), - }, - ], - }, - ]; - }, basePath: env.BASE_PATH, compiler: { styledComponents: true,