diff --git a/src/open_inwoner/conf/app/csp.py b/src/open_inwoner/conf/app/csp.py index 110155a9d7..592090b7f8 100644 --- a/src/open_inwoner/conf/app/csp.py +++ b/src/open_inwoner/conf/app/csp.py @@ -10,12 +10,13 @@ # # NOTE: make sure values are a tuple or list, and to quote special values like 'self' CSP_DEFAULT_SRC = ( - "'none'", + "'self'", ) # ideally we'd use BASE_URI but it'd have to be lazy or cause issues CSP_BASE_URI = ("'self'",) CSP_FONT_SRC = ("'self'",) CSP_FRAME_ANCESTORS = ["'self'"] CSP_FRAME_SRC = ["'self'"] +CSP_OBJECT_SRC = "'none'" CSP_SCRIPT_SRC = ( "'self'", "https://service.pdok.nl/brt/achtergrondkaart/wmts/v2_0/standaard/EPSG:28992/",