diff --git a/build.ps1 b/build.ps1 index 94d69e9..4776ba8 100644 --- a/build.ps1 +++ b/build.ps1 @@ -1,4 +1,3 @@ $version=poetry version -s docker build . --no-cache -t ajurna/cbwebreader -t ajurna/cbwebreader:$version -docker push ajurna/cbwebreader:$version -docker push ajurna/cbwebreader \ No newline at end of file +docker push ajurna/cbwebreader --all-tags \ No newline at end of file diff --git a/cbreader/settings/base.py b/cbreader/settings/base.py index d0fdf09..3d6e207 100644 --- a/cbreader/settings/base.py +++ b/cbreader/settings/base.py @@ -157,7 +157,7 @@ CSP_FONT_SRC = ("'self'",) CSP_SCRIPT_SRC = ("'self'", "'sha256-khnq7MWUoC3fJlH98ZjaCbVOvyd5+vnfVyue/ca55JA='") CSP_CONNECT_SRC = ("'self'",) CSP_INCLUDE_NONCE_IN = ['script-src'] -CSP_SCRIPT_SRC_ATTR = ("'self'", "'unsafe-inline'") +CSP_SCRIPT_SRC_ATTR = ("'self'",)# "'unsafe-inline'") PERMISSIONS_POLICY = { "accelerometer": [], @@ -179,6 +179,8 @@ PERMISSIONS_POLICY = { SESSION_COOKIE_HTTPONLY = True SESSION_COOKIE_SECURE = True +SESSION_COOKIE_SAMESITE = 'Strict' CSRF_COOKIE_HTTPONLY = True CSRF_COOKIE_SECURE = True +CSRF_COOKIE_SAMESITE = 'Strict' SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') diff --git a/comic/templates/comic/comic_list.html b/comic/templates/comic/comic_list.html index fed3d84..bb4023b 100644 --- a/comic/templates/comic/comic_list.html +++ b/comic/templates/comic/comic_list.html @@ -29,7 +29,7 @@