diff --git a/middleware/SecurityHeadersMiddleware.php b/middleware/SecurityHeadersMiddleware.php index 5390263..497c8ea 100644 --- a/middleware/SecurityHeadersMiddleware.php +++ b/middleware/SecurityHeadersMiddleware.php @@ -26,8 +26,10 @@ class SecurityHeadersMiddleware { $nonce = self::getNonce(); // Content Security Policy - restricts where resources can be loaded from - // Using nonce for inline scripts instead of unsafe-inline for better security - header("Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-{$nonce}'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self';"); + // Nonces are used for - -