110f5e12a634db49ea9aa1ea23ff4965f1c2befe galt Tue Aug 14 13:48:57 2018 -0700 changing cse to soe in domains, sometimes gi. ref #21876 diff --git src/lib/htmshell.c src/lib/htmshell.c index b04c93e..a4cc98b 100644 --- src/lib/htmshell.c +++ src/lib/htmshell.c @@ -998,31 +998,31 @@ dyStringAppend(policy, " netdna.bootstrapcdn.com"); // used by hgIntegrator dyStringAppend(policy, " maxcdn.bootstrapcdn.com"); // used by hgGateway dyStringAppend(policy, " fonts.gstatic.com"); // used by hgGateway dyStringAppend(policy, ";"); dyStringAppend(policy, " object-src 'none';"); */ dyStringAppend(policy, " img-src * data:;"); /* more secure method not used yet dyStringAppend(policy, " img-src 'self'"); // used by hgGene for modbaseimages in hg/hgc/lowelab.c hg/protein/lib/domains.c hg/hgGene/domains.c dyStringAppend(policy, " modbase.compbio.ucsf.edu"); -dyStringAppend(policy, " hgwdev.cse.ucsc.edu"); // used by visiGene +dyStringAppend(policy, " hgwdev.gi.ucsc.edu"); // used by visiGene dyStringAppend(policy, " genome.ucsc.edu"); // used by visiGene dyStringAppend(policy, " code.jquery.com"); // used by hgIntegrator dyStringAppend(policy, " www.google-analytics.com"); // used by google analytics dyStringAppend(policy, " stats.g.doubleclick.net"); // used by google analytics dyStringAppend(policy, ";"); */ return dyStringCannibalize(&policy); } char *getCspMetaString(char *policy) /* get the policy string as an html header meta tag */ { char meta[1024]; safef(meta, sizeof meta, "<meta http-equiv='Content-Security-Policy' content=\"%s\">\n", policy); // use double quotes around policy because it contains single-quoted values.