attempt to fix raffle

pull/2/head
Michael Q Larson 2014-12-22 16:47:02 -08:00
parent aebb9b3efd
commit 33324fdf01
1 changed files with 3 additions and 2 deletions

5
app.js
View File

@ -107,7 +107,8 @@ var trusted = [
"*.githubusercontent.com", "*.githubusercontent.com",
"'unsafe-eval'", "'unsafe-eval'",
"'unsafe-inline'", "'unsafe-inline'",
"*.rafflecopter.com" "*.rafflecopter.com",
"localhost:3001"
]; ];
//var connectSrc; //var connectSrc;
//if (process.env.NODE_ENV === 'development') { //if (process.env.NODE_ENV === 'development') {
@ -122,7 +123,7 @@ debug(trusted);
app.use(helmet.contentSecurityPolicy({ app.use(helmet.contentSecurityPolicy({
defaultSrc: trusted, defaultSrc: trusted,
scriptSrc: ['*.optimizely.com'].concat(trusted), scriptSrc: ['*.optimizely.com'].concat(trusted),
'connect-src': ["ws://*.rafflecopter.com", "wss://*.rafflecopter.com", "ws://www.freecodecamp.com", 'ws://localhost:3001/', 'http://localhost:3001/'], 'connect-src': ["ws://*.rafflecopter.com", "wss://*.rafflecopter.com","https://*.rafflecopter.com", "ws://www.freecodecamp.com", 'ws://localhost:3001/', 'http://localhost:3001', 'http://www.freecodecamp.com'],
styleSrc: trusted, styleSrc: trusted,
imgSrc: ['*.evernote.com', '*.amazonaws.com', "data:", '*.licdn.com', '*.gravatar.com', '*.youtube.com'].concat(trusted), imgSrc: ['*.evernote.com', '*.amazonaws.com', "data:", '*.licdn.com', '*.gravatar.com', '*.youtube.com'].concat(trusted),
fontSrc: ["'self", '*.googleapis.com'].concat(trusted), fontSrc: ["'self", '*.googleapis.com'].concat(trusted),