diff --git a/zola.toml b/zola.toml
index 196a7fb..735c837 100644
--- a/zola.toml
+++ b/zola.toml
@@ -40,11 +40,11 @@ socials = [
{ name = "mastodon", url = "https://mastodon.social/@jakobankarhem" },
]
+# CSP is served as an HTTP response header by nginx (see nix-config
+# modules/blog.nix), not as a tag. This is required so Cloudflare's
+# JavaScript Detections can parse the per-request nonce from the header and
+# stamp it onto the inline scripts it injects at the edge (whose hashes change
+# every request and cannot be pinned). A CSP cannot carry a nonce and
+# would co-enforce alongside the header, re-blocking the injected scripts.
[extra.content_security_policy]
-enable = true
-allowed_domains = [
- { directive = "base-uri", domains = ["'self'"] },
- { directive = "connect-src", domains = ["'self'", "cloudflareinsights.com"] },
- { directive = "form-action", domains = ["'self'"] },
- { directive = "script-src", domains = ["'self'", "static.cloudflareinsights.com", "'sha512-8DS7rgIrAmghBFwoOTujcf6D9rXvH8xm8JQ1Ja01h9QX8EzXldiszufYa4IFfKdLUKTTrnSFXLDkUEOTrZQ8Qg=='"] },
-]
+enable = false