diff --git a/src/aurora/config/settings.py b/src/aurora/config/settings.py index 0e23964e..846d680a 100644 --- a/src/aurora/config/settings.py +++ b/src/aurora/config/settings.py @@ -648,7 +648,8 @@ def show_ddt(request): # pragma: no-cover "csp.middleware.CSPMiddleware", ] CSP_DEFAULT_SRC = SOURCES -CSP_FRAME_SRC = [] +CSP_DEFAULT_SRC = ("'self'",) +CSP_FRAME_ANCESTORS = ("'none'",) # CSP_SCRIPT_SRC = SOURCES # CSP_STYLE_SRC = ( # "'self'",