File tree Expand file tree Collapse file tree 2 files changed +3
-4
lines changed Expand file tree Collapse file tree 2 files changed +3
-4
lines changed Original file line number Diff line number Diff line change @@ -13,5 +13,5 @@ customHeaders:
13
13
- key : ' X-Content-Type-Options'
14
14
value : ' nosniff'
15
15
- key : ' Content-Security-Policy'
16
- value: "upgrade-insecure-requests; default-src 'none'; prefetch-src 'self'; style-src 'self' 'unsafe-inline' *.shortbread.aws.dev; font-src 'self'; frame-src 'self' https://www.youtube-nocookie.com https://aws.demdex.net https://dpm.demdex.net; connect-src 'self' *.shortbread.aws.dev https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://d2c.aws.amazon.com https://vs.aws.amazon.com https://*.algolia.net https://*.algolianet.com *.amazonaws.com https://aws.amazon.com/ https://d2c-alpha.dse.marketing.aws.a2z.com https://aws-mktg-csds-alpha.integ.amazon.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; img-src 'self' https://img.shields.io https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; media-src 'self'; script-src 'self' *.shortbread.aws.dev https://a0.awsstatic.com/ https://aa0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://d2c.aws.amazon.com/;"
16
+ value: "upgrade-insecure-requests; default-src 'none'; style-src 'self' 'unsafe-inline' *.shortbread.aws.dev; font-src 'self'; frame-src 'self' https://www.youtube-nocookie.com https://aws.demdex.net https://dpm.demdex.net; connect-src 'self' *.shortbread.aws.dev https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://d2c.aws.amazon.com https://vs.aws.amazon.com https://*.algolia.net https://*.algolianet.com *.amazonaws.com https://aws.amazon.com/ https://d2c-alpha.dse.marketing.aws.a2z.com https://aws-mktg-csds-alpha.integ.amazon.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; img-src 'self' https://img.shields.io https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://a0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://aa0.awsstatic.com/; media-src 'self'; script-src 'self' *.shortbread.aws.dev https://a0.awsstatic.com/ https://aa0.awsstatic.com/ https://alpha.d2c.marketing.aws.dev/ https://d2c.aws.amazon.com/;"
17
17
# CSP also set in _document.tsx meta tag
Original file line number Diff line number Diff line change @@ -41,7 +41,8 @@ const ANALYTICS_CSP = {
41
41
'https://aa0.awsstatic.com/' ,
42
42
'https://alpha.d2c.marketing.aws.dev/' ,
43
43
'https://aws-mktg-csds-alpha.integ.amazon.com/' ,
44
- 'https://d2c-alpha.dse.marketing.aws.a2z.com'
44
+ 'https://d2c-alpha.dse.marketing.aws.a2z.com' ,
45
+ 'https://vs-alpha.aws.amazon.com'
45
46
] ,
46
47
img : [ 'https://aa0.awsstatic.com/' , 'https://alpha.d2c.marketing.aws.dev/' ] ,
47
48
script : [
@@ -61,7 +62,6 @@ const getCspContent = (context) => {
61
62
if ( process . env . BUILD_ENV !== 'production' ) {
62
63
return `upgrade-insecure-requests;
63
64
default-src 'none';
64
- prefetch-src 'self';
65
65
style-src 'self' 'unsafe-inline' ${ ANALYTICS_CSP . all . style . join ( ' ' ) } ;
66
66
font-src 'self' data:;
67
67
frame-src 'self' https://www.youtube-nocookie.com ${ ANALYTICS_CSP . all . frame . join (
@@ -85,7 +85,6 @@ const getCspContent = (context) => {
85
85
// Have to keep track of CSP inside customHttp.yml as well
86
86
return `upgrade-insecure-requests;
87
87
default-src 'none';
88
- prefetch-src 'self';
89
88
style-src 'self' 'unsafe-inline' ${ ANALYTICS_CSP . all . style . join ( ' ' ) } ;
90
89
font-src 'self';
91
90
frame-src 'self' https://www.youtube-nocookie.com ${ ANALYTICS_CSP . all . frame . join (
You can’t perform that action at this time.
0 commit comments