diff --git a/.htaccess b/.htaccess index 26321e5..a7c8f5a 100755 --- a/.htaccess +++ b/.htaccess @@ -17,13 +17,11 @@ ServerSignature Off Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" Header set Content-Security-Policy "default-src 'self'; \ - script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net ; \ - style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; \ - font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net; \ - connect-src 'self' https://cdn.jsdelivr.net; \ + script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; \ + style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; \ + font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; \ + connect-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; \ img-src 'self' data: https:" Header set Referrer-Policy "strict-origin-when-cross-origin" - - -https://cdnjs.cloudflare.com \ No newline at end of file + \ No newline at end of file