From 6bfd87b68ea307baa876aad3252efa84bcab52d1 Mon Sep 17 00:00:00 2001 From: Ruggero Tomaselli Date: Sun, 29 Jan 2023 13:54:40 +0100 Subject: [PATCH] fix: Remove 'upgrade-insecure-requests' for self-host --- studio/next.config.js | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/studio/next.config.js b/studio/next.config.js index 99b4b7d2513..e9ff06245e1 100644 --- a/studio/next.config.js +++ b/studio/next.config.js @@ -12,6 +12,14 @@ const withTM = require('next-transpile-modules')(['ui', 'common']) // https://nextjs.org/docs/api-reference/next.config.js/introduction // https://docs.sentry.io/platforms/javascript/guides/nextjs/ +const csp = [ + "frame-ancestors 'none';", + // IS_PLATFORM + process.env.NEXT_PUBLIC_IS_PLATFORM === 'true' ? 'upgrade-insecure-requests;' : '', +] + .filter(Boolean) + .join(' ') + const nextConfig = { async redirects() { return [ @@ -137,12 +145,7 @@ const nextConfig = { }, { key: 'Content-Security-Policy', - value: ` - frame-ancestors 'none'; - upgrade-insecure-requests; - ` - .replace(/\s{2,}/g, ' ') - .trim(), + value: csp, }, { key: 'Referrer-Policy',