Skip to content

Commit

Permalink
All: add CSP exceptions for loading klavika font from typekit
Browse files Browse the repository at this point in the history
  • Loading branch information
timmywil committed Dec 25, 2024
1 parent 80715f1 commit ca0852d
Showing 1 changed file with 7 additions and 2 deletions.
9 changes: 7 additions & 2 deletions jquery/functions.php
Original file line number Diff line number Diff line change
Expand Up @@ -289,9 +289,14 @@ function twentyeleven_content_security_policy() {
$report_url = 'https://csp-report-api.openjs-foundation.workers.dev/';
$policy = array(
'default-src' => "'self'",
'script-src' => "'self' code.jquery.com",
'style-src' => "'self' code.jquery.com",
// Allow scripts and inline scripts for typekit
'script-src' => "'self' 'unsafe-inline' code.jquery.com use.typekit.net",
// Allow inline styles for typekit
'style-src' => "'self' 'unsafe-inline' code.jquery.com",
// Leaving out typekit img-src, which only loads the p.gif for analytics
'img-src' => "'self' code.jquery.com",
// Allow fonts from typekit
'font-src' => "'self' use.typekit.net",
'object-src' => "'none'",
'frame-ancestors' => "'none'",
'block-all-mixed-content' => '',
Expand Down

0 comments on commit ca0852d

Please sign in to comment.