fix (2fa.directory): Allow api.2fa.directory, and remove 2fa.directory

pull/3132/head
GeekCorner 2 years ago committed by GitHub
parent 367e1ce289
commit 2ee0d53c5f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -50,7 +50,7 @@ impl Fairing for AppHeaders {
// Have I Been Pwned and Gravator to allow those calls to work. // Have I Been Pwned and Gravator to allow those calls to work.
// # Connect src: // # Connect src:
// Leaked Passwords check: api.pwnedpasswords.com // Leaked Passwords check: api.pwnedpasswords.com
// 2FA/MFA Site check: 2fa.directory // 2FA/MFA Site check: api.2fa.directory
// # Mail Relay: https://bitwarden.com/blog/add-privacy-and-security-using-email-aliases-with-bitwarden/ // # Mail Relay: https://bitwarden.com/blog/add-privacy-and-security-using-email-aliases-with-bitwarden/
// app.simplelogin.io, app.anonaddy.com, api.fastmail.com, quack.duckduckgo.com // app.simplelogin.io, app.anonaddy.com, api.fastmail.com, quack.duckduckgo.com
let csp = format!( let csp = format!(
@ -73,7 +73,7 @@ impl Fairing for AppHeaders {
{icon_service_csp}; \ {icon_service_csp}; \
connect-src 'self' \ connect-src 'self' \
https://api.pwnedpasswords.com \ https://api.pwnedpasswords.com \
https://2fa.directory \ https://api.2fa.directory \
https://app.simplelogin.io/api/ \ https://app.simplelogin.io/api/ \
https://app.anonaddy.com/api/ \ https://app.anonaddy.com/api/ \
https://api.fastmail.com/ \ https://api.fastmail.com/ \

Loading…
Cancel
Save