Advertisement
Guest User

Untitled

a guest
May 29th, 2016
69
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.39 KB | None | 0 0
  1. before_filter :set_csp
  2. def set_csp
  3. csp = "default-src 'self';"
  4. csp += "script-src 'self' 'unsafe-inline' 'unsafe-eval' https://yandex.st/swfobject;"
  5. csp += "style-src 'self' 'unsafe-inline';"
  6. csp += "frame-src 'self' https://www.youtube.com https://video.serials.today http://blackoctopus.cc http://moonwalk.cc"
  7.  
  8. response.headers['Content-Security-Policy'] = csp
  9. end
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement