diff --git a/docker-compose.yml b/docker-compose.yml index 0c04cfd..3dda839 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -99,6 +99,7 @@ services: #- QUEUE_CONNECTION=sync #- SECURITY_HEADER_HSTS_ENABLE=false #- SECURITY_HEADER_CSP_CONNECT_SRC= + #- SECURITY_HEADER_CSP_FRAME_ANCESTORS= #- SECURITY_HEADER_SCRIPT_SRC_ALLOW= #- SESSION_SECURE_COOKIE=false #- MAIL_DRIVER=smtp diff --git a/inject.sh b/inject.sh index 9a99de6..846d25b 100755 --- a/inject.sh +++ b/inject.sh @@ -133,6 +133,9 @@ if [ "$SECURITY_HEADER_CSP_CONNECT_SRC" != '' ]; then if [ "$SECURITY_HEADER_SCRIPT_SRC_ALLOW" != '' ]; then replace_or_insert "SECURITY_HEADER_SCRIPT_SRC_ALLOW" "$SECURITY_HEADER_SCRIPT_SRC_ALLOW" fi +if [ "$SECURITY_HEADER_CSP_FRAME_ANCESTORS" != '' ]; then + replace_or_insert "SECURITY_HEADER_CSP_FRAME_ANCESTORS" "$SECURITY_HEADER_CSP_FRAME_ANCESTORS" + fi if [ "$SESSION_SECURE_COOKIE" != '' ]; then replace_or_insert "SESSION_SECURE_COOKIE" "$SESSION_SECURE_COOKIE" fi