amended policy
[mirror/dsa-puppet.git] / modules / roles / templates / static-mirroring / vhost / static-vhosts-simple.erb
index a84e174..3cc2400 100644 (file)
        # Versioned request
        RewriteRule ^/source/([a-z0-9-]+)/([a-zA-Z0-9.+:~-]+)$ /${source-map:$1/$2} [L,R,NE]
 
-       Header always set Content-Security-Policy "default-src 'self';"
+       Header always set Content-Security-Policy "default-src 'self'; media-src 'none'; object-src 'none';"
 </Macro>
 
 <%=