Skip to content

Commit

Permalink
fix: replace malicious polyfill cdn (#347)
Browse files Browse the repository at this point in the history
  • Loading branch information
andreiio authored Jun 28, 2024
1 parent f20751c commit 52be305
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 4 deletions.
6 changes: 3 additions & 3 deletions app/Http/Middleware/SecurityHeaders.php
Original file line number Diff line number Diff line change
Expand Up @@ -31,9 +31,9 @@ public function handle($request, Closure $next)
if (app()->environment(['production', 'development'])) {
$response->headers->add(
[
'Content-Security-Policy' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com polyfill.io maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com;",
'X-Content-Security-Policy' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com polyfill.io maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com",
'X-WebKit-CSP' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com helpforhealth.local impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com polyfill.io maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com"
'Content-Security-Policy' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com;",
'X-Content-Security-Policy' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com",
'X-WebKit-CSP' => "default-src fonts.googleapis.com *.amazonaws.com *.google.com www.googletagmanager.com www.google-analytics.com helpforhealth.local impreunapentrusanatate.ro dev.impreunapentrusanatate.ro; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com www.googletagmanager.com *.google-analytics.com www.gstatic.com maps.googleapis.com cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com; object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.tiny.cloud; img-src 'self' data: *.amazonaws.com maps.googleapis.com maps.gstatic.com sp.tinymce.com *.google-analytics.com; frame-src 'self' *.google.com www.googletagmanager.com www.google-analytics.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com"
]
);
}
Expand Down
2 changes: 1 addition & 1 deletion resources/views/frontend/clinic-details.blade.php
Original file line number Diff line number Diff line change
Expand Up @@ -161,7 +161,7 @@
@endsection

@section('head-scripts')
<script src="https://polyfill.io/v3/polyfill.min.js?features=default"></script>
<script src="https://cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js?features=default"></script>
<script
src="https://maps.googleapis.com/maps/api/js?key={{ config('maps.api_key') }}&callback=initMap&libraries=&v=weekly"
defer
Expand Down

0 comments on commit 52be305

Please sign in to comment.