webwhiz
webwhiz copied to clipboard
Widget nginx: More Content-Security-Policy header
Improves on #225 (PR set as draft, to wait for the other PR to be merged)
Restrict the hosts that the widget is allowed to contact.
Also, set stylesheet from cloudflare to be loaded over https, also in development.