csp: do not use java applet, <base>

This commit is contained in:
hiromi-mi 2020-06-20 10:19:54 +09:00
parent f0929c6bab
commit 10d77cf183

2
app.py
View file

@ -104,6 +104,8 @@ csp = {
"script-src": "'self'", # to use nonce
"style-src": "'unsafe-inline'", # for old browsers without support style-src-attr
"style-src-elem": "'self'",
"base-uri": "'none'",
"object-src" : "'none'",
}
talisman = Talisman(