Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions docusaurus.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,26 @@ const config = {
href: '/favicons/apple-touch-icon.png',
},
},
{
tagName: 'meta',
attributes: {
'http-equiv': 'Content-Security-Policy',
// Defence in depth for content this site does not author: architecture
// MDX and image assets are mirrored from cncf/architecture, and several
// data/*.json files supply href and src values rendered by src/components.
// These three directives need no allowance for inline or bundled script,
// so they hold without constraining Docusaurus hydration or local search.
// script-src is deliberately omitted: Docusaurus emits inline bootstrap
// scripts, so it could only ship with 'unsafe-inline', which would add no
// protection. frame-ancestors is omitted because browsers ignore it when
// delivered via <meta http-equiv>; it needs a real response header.
content: [
"base-uri 'self'",
"object-src 'none'",
"form-action 'self'",
].join('; '),
},
},
{
tagName: 'script',
attributes: {
Expand Down
Loading