diff --git a/gradle.properties b/gradle.properties index e7bb9278c..fbc6d7e99 100644 --- a/gradle.properties +++ b/gradle.properties @@ -14,6 +14,6 @@ # limitations under the License. # -version=3.16.1 +version=3.16.2 groupId=com.nike.cerberus artifactId=cms diff --git a/src/main/java/com/nike/cerberus/security/SecurityHttpHeaders.java b/src/main/java/com/nike/cerberus/security/SecurityHttpHeaders.java index 68ab519c3..71a3c6489 100644 --- a/src/main/java/com/nike/cerberus/security/SecurityHttpHeaders.java +++ b/src/main/java/com/nike/cerberus/security/SecurityHttpHeaders.java @@ -48,7 +48,14 @@ public class SecurityHttpHeaders extends DefaultHttpHeaders { * https://en.wikipedia.org/wiki/Content_Security_Policy */ private static final String CONTENT_SECURITY_POLICY_HEADER_NAME = "Content-Security-Policy"; - private static final String CONTENT_SECURITY_POLICY_HEADER_VALUE = "default-src 'none'; connect-src 'self'; font-src https://web.nike.com; img-src 'self'; script-src 'self'; style-src 'unsafe-inline' https://web.nike.com/; worker-src 'self' blob:; frame-ancestors 'none';"; + private static final String CONTENT_SECURITY_POLICY_HEADER_VALUE = "default-src 'none';" + + " connect-src 'self';" + + " font-src https://web.nike.com;" + + " img-src 'self';" + + " script-src 'self';" + + " style-src 'unsafe-inline' https://web.nike.com/;" + + " worker-src 'self' blob:; frame-ancestors 'none';" + + " child-src 'self' blob:;"; /** * Referrer Policy header can restrict referrer information sent by browser