diff --git a/api/nginx.conf b/api/nginx.conf index 29a0cbf5b..dde34bbd5 100644 --- a/api/nginx.conf +++ b/api/nginx.conf @@ -37,7 +37,7 @@ http { set $STYLE_SRC_ELEM "style-src 'self'"; set $STYLE_SRC_ATTR "style-src-attr 'unsafe-inline'"; set $CONNECT "connect-src 'self' *.API_URL *.ROOT_URL"; - add_header 'Content-Security-Policy' "default-src 'self' *.API_URL; ${IMG}; ${WORKER}; ${CONNECT} ${STYLE_SRC_ATTR}; ${STYLE_SRC_ELEM}; ${FONT}; upgrade-insecure-requests;" always; + add_header 'Content-Security-Policy' "default-src 'self' *.API_URL; ${IMG}; ${WORKER}; ${CONNECT}; ${STYLE_SRC_ATTR}; ${STYLE_SRC_ELEM}; ${FONT}; upgrade-insecure-requests;" always; location / { if ($request_uri ~ ^/(.*)\.html) {