From 6478b3e3ef6554fa4db6c4b0dffaed8728ab15a6 Mon Sep 17 00:00:00 2001 From: Olblak Date: Wed, 31 Dec 2025 14:19:26 +0100 Subject: [PATCH] fix: allow youtube frame Signed-off-by: Olblak --- layouts/index.headers | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/layouts/index.headers b/layouts/index.headers index 41435bca0..d35db8f77 100644 --- a/layouts/index.headers +++ b/layouts/index.headers @@ -2,7 +2,7 @@ Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block - Content-Security-Policy: default-src 'self' https://asciinema.org; frame-ancestors https://jamstackthemes.dev; manifest-src 'self'; connect-src 'self' https://plausible.io https://cdn.matomo.cloud https://updatecli.matomo.cloud ; font-src 'self'; img-src 'self' https://cdn.matomo.cloud https://updatecli.matomo.cloud data:; script-src 'self' https://cdn.matomo.cloud https://updatecli.matomo.cloud https://plausible.io https://asciinema.org https://www.updatecli.io 'unsafe-inline'; style-src 'self' + Content-Security-Policy: default-src 'self' https://asciinema.org; frame-src 'self' https://asciinema.org https://www.youtube.com https://www.youtube-nocookie.com; frame-ancestors https://jamstackthemes.dev; manifest-src 'self'; connect-src 'self' https://plausible.io https://cdn.matomo.cloud https://updatecli.matomo.cloud ; font-src 'self'; img-src 'self' https://cdn.matomo.cloud https://updatecli.matomo.cloud data:; script-src 'self' https://cdn.matomo.cloud https://updatecli.matomo.cloud https://plausible.io https://asciinema.org https://www.updatecli.io 'unsafe-inline'; style-src 'self' X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin Feature-Policy: geolocation 'self'