-
-
Notifications
You must be signed in to change notification settings - Fork 136
Expand file tree
/
Copy pathnetlify.toml
More file actions
30 lines (26 loc) · 1.58 KB
/
netlify.toml
File metadata and controls
30 lines (26 loc) · 1.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
[build.environment]
# bypass npm auto install
NPM_FLAGS = "--version"
NODE_VERSION = "20"
[build]
publish = "dist"
command = "bun install && npx puppeteer browsers install chrome && bun run build"
[[redirects]]
from = "/*"
to = "/index.html"
status = 200
[[headers]]
for = "/manifest.webmanifest"
[headers.values]
Content-Type = "application/manifest+json"
[[headers]]
for = "/*"
[headers.values]
Content-Security-Policy = "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.googletagmanager.com https://www.google-analytics.com https://cdn.carbonads.com https://cdn.jsdelivr.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.googletagmanager.com https://www.google-analytics.com https://cdn.carbonads.com https://cdn.jsdelivr.net; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src 'self' data: https: https://cdn.carbonads.com https://cdn.jsdelivr.net; font-src 'self' data: https://cdn.jsdelivr.net; connect-src 'self' https://www.google-analytics.com https://cdn.jsdelivr.net https://srv.carbonads.net; upgrade-insecure-requests"
Referrer-Policy = "strict-origin-when-cross-origin"
X-Content-Type-Options = "nosniff"
X-Frame-Options = "DENY"
Cross-Origin-Opener-Policy = "same-origin"
Cross-Origin-Resource-Policy = "same-site"
Strict-Transport-Security = "max-age=31536000; includeSubDomains; preload"
Permissions-Policy = "geolocation=(), microphone=(), camera=(), interest-cohort=()"