// Copyright (c) 2018, Compiler Explorer Authors // All rights reserved. // // Redistribution and use in source and binary forms, with or without // modification, are permitted provided that the following conditions are met: // // * Redistributions of source code must retain the above copyright notice, // this list of conditions and the following disclaimer. // * Redistributions in binary form must reproduce the above copyright // notice, this list of conditions and the following disclaimer in the // documentation and/or other materials provided with the distribution. // // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" // AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE // IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE // ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE // LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR // CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF // SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS // INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN // CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) // ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE // POSSIBILITY OF SUCH DAMAGE. export const data = { 'default-src': ["'self'", 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com'], 'style-src': [ "'self'", "'unsafe-inline'", 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', ], 'script-src': [ "'self'", "'unsafe-inline'", 'data:', 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', 'https://*.twitter.com', 'https://www.google-analytics.com', 'https://apis.google.com', 'https://ssl.google-analytics.com', 'https://sentry.io/', ], 'img-src': [ "'self'", 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', 'data:', 'https://www.google-analytics.com/', 'https://syndication.twitter.com', 'https://ssl.google-analytics.com', 'https://csi.gstatic.com', ], 'font-src': [ "'self'", 'data:', 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', 'https://fonts.gstatic.com', 'https://themes.googleusercontent.com', ], 'frame-src': [ "'self'", 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', 'https://www.google-analytics.com', 'https://accounts.google.com/', 'https://content.googleapis.com/', 'https://sentry.io', 'https://platform.twitter.com/', 'https://syndication.twitter.com/', ], 'connect-src': [ "'self'", '*', 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', 'https://api.github.com', ], 'media-src': [ "'self'", 'https://ssl.gstatic.com', 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com', ], }; export const policy = Object.values(data) .map((value, policyKey) => `${policyKey} ${value.join(' ')}`) .join(';');