diff --git a/static/.htaccess b/static/.htaccess index 1702b859..eccc1109 100644 --- a/static/.htaccess +++ b/static/.htaccess @@ -67,9 +67,9 @@ AddType 'image/svg+xml; charset=UTF8' svg svgz Header set Referrer-Policy "no-referrer" - Header set Content-Security-Policy "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" - Header set X-Content-Security-Policy "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" - Header set X-WebKit-CSP "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" + Header set Content-Security-Policy "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com cdn.ampproject.org; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" + Header set X-Content-Security-Policy "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com cdn.ampproject.org; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" + Header set X-WebKit-CSP "default-src 'self' https://www.mv-wollbach.de; script-src 'self' 'unsafe-inline' s3.amazonaws.com www.google.com www.gstatic.com cdn.ampproject.org; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn-images.mailchimp.com gooding.s3.amazonaws.com; img-src 'self' gooding.s3.amazonaws.com www.google.com www.w3basis.de jigsaw.w3.org lh3.googleusercontent.com; media-src youtube-nocookie.com; frame-src erweiterungen.gooding.de www.youtube-nocookie.com www.google.com; font-src 'self' fonts.gstatic.com; connect-src 'self'" Header always set X-Content-Type-Options "nosniff" diff --git a/themes/mv-wollbach/layouts/_default/baseof.html b/themes/mv-wollbach/layouts/_default/baseof.html index 9544450d..e3955273 100644 --- a/themes/mv-wollbach/layouts/_default/baseof.html +++ b/themes/mv-wollbach/layouts/_default/baseof.html @@ -1,6 +1,6 @@ -{{- partial "head.html" . -}} +{{- partial "header.html" . -}}
{{- partial "navigation.html" . -}}