From 5d2d3ec875310de07fe79ae605dfbc0f1df585c5 Mon Sep 17 00:00:00 2001 From: Literallie Date: Wed, 18 Oct 2017 17:45:57 +0200 Subject: CSP: Upgrade insecure requests if possible Config option; default is to only upgrade if usessl --- lib/config/default.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) (limited to 'lib/config') diff --git a/lib/config/default.js b/lib/config/default.js index e207dfc6..217d11d0 100644 --- a/lib/config/default.js +++ b/lib/config/default.js @@ -20,8 +20,9 @@ module.exports = { defaultSrc: ["'self'"], scriptSrc: ["'self'"], styleSrc: ["'self'", "'unsafe-inline'"], - fontSrc: ["'self'"] - } + fontSrc: ["'self'"], + }, + upgradeInsecureRequests: 'auto' }, protocolusessl: false, usecdn: true, -- cgit v1.2.3