helmet.go removed wildcard directive.

This commit is contained in:
Ankit Patial 2025-05-18 22:48:11 +05:30
parent f8cdf3a511
commit ddb4b35181

View File

@ -268,7 +268,7 @@ func (csp *CSP) value() string {
sb.WriteString(fmt.Sprintf(
"style-src %s; ",
cspNormalised(csp.StyleSrc, []string{"self", "https:", "unsafe-inline"}),
cspNormalised(csp.StyleSrc, []string{"self", "unsafe-inline"}),
))
sb.WriteString(fmt.Sprintf(
@ -288,7 +288,7 @@ func (csp *CSP) value() string {
sb.WriteString(fmt.Sprintf(
"font-src %s; ",
cspNormalised(csp.FontSrc, []string{"self", "https:", "data:"}),
cspNormalised(csp.FontSrc, []string{"self", "data:"}),
))
sb.WriteString(fmt.Sprintf(