Commit daa6cc2e by CubeSky

Upgrade CSP Protection

1 parent 3b0f153a
Showing with 28 additions and 16 deletions
......@@ -37,4 +37,4 @@
.其实 阿米巴·轻 是悄悄更新的~
>div.ui.divider
>p
.版本: Version 12
\ No newline at end of file
.版本: Version 14
\ No newline at end of file
......@@ -2,13 +2,25 @@
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1.0, user-scalable=0">
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; connect-src 'self' *.icesimba.com *.utilapi.bid wss://mq.utilapi.bid/; frame-src 'self' *.utilapi.bid *.icesimba.com; img-src 'self' data: https://static.utilapi.bid/amiba/logo.png; script-src 'self' https://www.googletagmanager.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/;font-src 'self' https://fonts.gstatic.com/ data: ;object-src 'none';upgrade-insecure-requests;block-all-mixed-content;">
<meta http-equiv="Content-Security-Policy" content="
default-src 'self';
connect-src 'self' *.icesimba.com *.utilapi.bid wss://mq.utilapi.bid/;
frame-src 'none';
img-src 'self' data: https://static.utilapi.bid/amiba/logo.png;
script-src 'self' https://cdnjs.loli.net https://cdn.polyfill.io https://www.googletagmanager.com;
style-src 'self' 'unsafe-inline' https://cdnjs.loli.net https://fonts.googleapis.com;
font-src 'self' https://fonts.gstatic.com https://cdnjs.loli.net data: ;
object-src 'none';
upgrade-insecure-requests;
block-all-mixed-content;
require-sri-for script style;
">
<title>阿米吧·轻</title>
<link rel="stylesheet" href="/css/semantic.min.css">
<link rel="stylesheet" href="/css/chartist.css">
<link crossorigin="anonymous" rel="stylesheet" href="https://cdnjs.loli.net/ajax/libs/semantic-ui/2.3.1/semantic.min.css" integrity="sha256-oDCP2dNW17Y1QhBwQ+u2kLaKxoauWvIGks3a4as9QKs=">
<link crossorigin="anonymous" rel="stylesheet" href="https://cdnjs.loli.net/ajax/libs/chartist/0.11.0/chartist.min.css" integrity="sha256-Te9+aTaL9j0U5PzLhtAHt+SXlgIT8KT9VkyOZn68hak=">
<link rel="stylesheet" href="/css/chartist-plugin-tooltip.css">
<link rel="stylesheet" href="/css/main.css">
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-113950860-1"></script>
<script crossorigin="anonymous" async src="https://www.googletagmanager.com/gtag/js?id=UA-113950860-1" integrity="sha256-W9LUZ0aGmmWQ2+rNPsEibj97ay6Ld1faPKBZd4lme/U="></script>
</head>
<body style="background-color: transparent !important;">
......@@ -40,17 +52,17 @@
</div>
</div>
</div>
<script src="/js/jquery-3.3.1.min.js"></script>
<script src="/js/semantic.min.js"></script>
<script src="/js/page.js"></script>
<script src="/js/chartist.min.js"></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/jquery/3.3.1/jquery.min.js" integrity="sha256-FgpCb/KJQlLNfOu91ta32o/NMZxltwRo8QtmkMRdAu8="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/semantic-ui/2.3.1/semantic.min.js" integrity="sha256-RKNmL9+6j/3jB72OcIg8OQr91Bi4OgFPnKQOFS1O+fo="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/page.js/1.8.6/page.min.js" integrity="sha256-jP09BJovLRZvP/pGE3iLR8StyaQ52CwcuKHESXU7HAo="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/chartist/0.11.0/chartist.min.js" integrity="sha256-UzffRueYhyZDw8Cj39UCnnggvBfa1fPcDQ0auvCbvCc="></script>
<script src="/js/chartist-plugin-tooltip.min.js"></script>
<script src="/js/ef.min.js"></script>
<script src="/js/moment-with-locales.js"></script>
<script src="/js/axios.min.js"></script>
<script src="/js/sockjs.min.js"></script>
<script src="/js/stomp.min.js"></script>
<script src="/js/localstorage-polyfill.js"></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/ef.js/0.7.2/ef.min.js" integrity="sha256-5G2XDZX4MhiAyVlitIB5yHcQN1wHDd1Bm2r0ZI4i1i4="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/moment.js/2.22.1/moment-with-locales.min.js" integrity="sha256-ZykW30UBCXWkPGsVyVPdJlUrce9/PawgYCEzinA4pnU="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/axios/0.18.0/axios.min.js" integrity="sha256-mpnrJ5DpEZZkwkE1ZgkEQQJW/46CSEh/STrZKOB/qoM="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/sockjs-client/1.1.4/sockjs.min.js" integrity="sha256-KWJavOowudybFMUCd547Wvd/u8vUg/2g0uSWYU5Ae+w="></script>
<script crossorigin="anonymous" src="https://cdnjs.loli.net/ajax/libs/stomp.js/2.3.3/stomp.min.js" integrity="sha256-nkP8cj5xaTdWK/BsZl+57ZCE/Y/i4UNtbNTpgH+6Taw="></script>
<script src="https://cdn.polyfill.io/v2/polyfill.min.js"></script>
<script src="/js/main.js"></script>
</body>
......
Markdown is supported
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!