From 20599571f7e35a020e3639c64abd054381f3fe08 Mon Sep 17 00:00:00 2001
From: Tommy <contact@tommytran.io>
Date: Sun, 23 Jun 2024 12:54:06 -0700
Subject: [PATCH] Rearrange CSP policies

Signed-off-by: Tommy <contact@tommytran.io>
---
 static/_headers | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/static/_headers b/static/_headers
index d8f1f43..81c8485 100644
--- a/static/_headers
+++ b/static/_headers
@@ -1,6 +1,6 @@
 /*
   Strict-Transport-Security : max-age=63072000; includeSubDomains; preload
-  Content-Security-Policy : default-src 'none'; connect-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; form-action 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; base-uri 'none'
+  Content-Security-Policy : default-src 'none'; connect-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; base-uri 'none'; block-all-mixed-content; form-action 'none'; frame-ancestors 'none'; upgrade-insecure-requests
   X-Content-Type-Options : nosniff
   Referrer-Policy : no-referrer
   X-Frame-Options : DENY