diff --git a/src/middleware/apiCsp.ts b/src/middleware/apiCsp.ts index deeb791..6d5f1ef 100644 --- a/src/middleware/apiCsp.ts +++ b/src/middleware/apiCsp.ts @@ -1,6 +1,6 @@ import {NextFunction, Request, Response} from 'express'; export function apiCspMiddleware(req: Request, res: Response, next: NextFunction) { - res.header("Content-Security-Policy", "script-src 'none'"); + res.header("Content-Security-Policy", "script-src 'none'; object-src 'none'"); next(); } \ No newline at end of file