diff --git a/zola.toml b/zola.toml index 196a7fb..735c837 100644 --- a/zola.toml +++ b/zola.toml @@ -40,11 +40,11 @@ socials = [ { name = "mastodon", url = "https://mastodon.social/@jakobankarhem" }, ] +# CSP is served as an HTTP response header by nginx (see nix-config +# modules/blog.nix), not as a tag. This is required so Cloudflare's +# JavaScript Detections can parse the per-request nonce from the header and +# stamp it onto the inline scripts it injects at the edge (whose hashes change +# every request and cannot be pinned). A CSP cannot carry a nonce and +# would co-enforce alongside the header, re-blocking the injected scripts. [extra.content_security_policy] -enable = true -allowed_domains = [ - { directive = "base-uri", domains = ["'self'"] }, - { directive = "connect-src", domains = ["'self'", "cloudflareinsights.com"] }, - { directive = "form-action", domains = ["'self'"] }, - { directive = "script-src", domains = ["'self'", "static.cloudflareinsights.com", "'sha512-8DS7rgIrAmghBFwoOTujcf6D9rXvH8xm8JQ1Ja01h9QX8EzXldiszufYa4IFfKdLUKTTrnSFXLDkUEOTrZQ8Qg=='"] }, -] +enable = false