feat: Add Content Security Policy header and move Plausible script to HTML head with beforeInteractive strategy.

This commit is contained in:
Hördle Bot
2025-11-25 22:19:34 +01:00
parent 1d62aca2fb
commit ffb7be602f
2 changed files with 13 additions and 2 deletions

View File

@@ -15,6 +15,15 @@ const nextConfig: NextConfig = {
},
async headers() {
return [
{
source: '/:path*',
headers: [
{
key: 'Content-Security-Policy',
value: "script-src 'self' 'unsafe-inline' 'unsafe-eval' https://plausible.elpatron.me; connect-src 'self' https://plausible.elpatron.me;",
},
],
},
{
source: '/uploads/:path*.mp3',
headers: [