From a9bfcc730be8218597fd6e96a0158f9b42bcc9f5 Mon Sep 17 00:00:00 2001 From: Laura Witulski Morales Date: Fri, 12 Dec 2025 09:05:39 +0100 Subject: [PATCH] fix: removes duplication and modifies img-src --- serverless.yml | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/serverless.yml b/serverless.yml index 33d16e3..4c08cbd 100644 --- a/serverless.yml +++ b/serverless.yml @@ -610,13 +610,10 @@ resources: ModeBlock: true Override: false ContentSecurityPolicy: - ContentSecurityPolicy: "default-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' ${env:IMAGE_SERVICE_URL} ${env:AVATAR_URL} ${env:AVATAR_BUCKET_URL} data:; connect-src 'self' https://${env:BACKEND_DOMAIN_NAME} ${env:MICROSOFT_LOGIN_URL}; + ContentSecurityPolicy: "default-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' ${env:IMAGE_URL} ${env:AVATAR_URL} ${env:AVATAR_BUCKET_URL} data:; connect-src 'self' https://${env:BACKEND_DOMAIN_NAME} ${env:MICROSOFT_LOGIN_URL}; Override: true CustomHeadersConfig: Items: - Header: Cache-Control Value: 'no-store' Override: true - - Header: Content-Security-Policy - Value: "default-src 'self'" - Override: true