helmet.go removed wildcard directive.

This commit is contained in:
Ankit Patial 2025-05-18 22:48:11 +05:30
parent f8cdf3a511
commit ddb4b35181

View File

@ -268,7 +268,7 @@ func (csp *CSP) value() string {
sb.WriteString(fmt.Sprintf( sb.WriteString(fmt.Sprintf(
"style-src %s; ", "style-src %s; ",
cspNormalised(csp.StyleSrc, []string{"self", "https:", "unsafe-inline"}), cspNormalised(csp.StyleSrc, []string{"self", "unsafe-inline"}),
)) ))
sb.WriteString(fmt.Sprintf( sb.WriteString(fmt.Sprintf(
@ -288,7 +288,7 @@ func (csp *CSP) value() string {
sb.WriteString(fmt.Sprintf( sb.WriteString(fmt.Sprintf(
"font-src %s; ", "font-src %s; ",
cspNormalised(csp.FontSrc, []string{"self", "https:", "data:"}), cspNormalised(csp.FontSrc, []string{"self", "data:"}),
)) ))
sb.WriteString(fmt.Sprintf( sb.WriteString(fmt.Sprintf(