feat(app): add Content-Security-Policy meta tag

Restricts script, style, img, connect, media, and frame sources to
known-safe origins. Blocks object embeds and enforces base-uri self.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Dorian
2026-03-04 22:18:58 +00:00
co-authored by Claude Opus 4.6
parent e7496883c4
commit ece4540388
+1
View File
@@ -10,6 +10,7 @@
<meta name="apple-mobile-web-app-status-bar-style" content="black-translucent" />
<meta name="apple-mobile-web-app-title" content="AIUI" />
<meta name="description" content="AI chat interface with rich content surfaces" />
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://image.tmdb.org https://covers.openlibrary.org https://is1-ssl.mzstatic.com https://upload.wikimedia.org https://books.google.com https://*.googleusercontent.com; font-src 'self'; connect-src 'self' https://mempool.space https://itunes.apple.com https://openlibrary.org https://www.googleapis.com https://en.wikipedia.org https://openrouter.ai wss:; media-src 'self' blob: https:; frame-src https://www.youtube-nocookie.com https://*.odysee.com; object-src 'none'; base-uri 'self';" />
<link rel="icon" href="/favicon.svg" type="image/svg+xml" />
<link rel="apple-touch-icon" href="/apple-touch-icon-180x180.png" />
<title>AIUI</title>