From a067aaa31ae8285ee9d0069df8901730c8a9e18e Mon Sep 17 00:00:00 2001 From: anmol Date: Sun, 4 Nov 2018 23:42:57 +0530 Subject: [PATCH] Random string --- conf/nginx.conf | 2 +- scripts/install | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/conf/nginx.conf b/conf/nginx.conf index 8237e6d..bf1f473 100755 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -16,7 +16,7 @@ add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "same-origin" always; add_header X-Download-Options "noopen" always; - add_header Content-Security-Policy "default-src 'none'; base-uri 'self'; form-action *; frame-ancestors 'none'; img-src 'self' data: https:; media-src 'self' https:; style-src 'self' 'unsafe-inline'; font-src 'self'; script-src 'self'; connect-src 'self' wss://example.tld; upgrade-insecure-requests;" always; + add_header Content-Security-Policy "default-src 'none'; base-uri 'self'; form-action *; frame-ancestors 'none'; img-src 'self' data: https:; media-src 'self' https:; style-src 'self' 'unsafe-inline'; font-src 'self'; script-src 'self'; connect-src 'self' wss://__DOMAIN__; upgrade-insecure-requests;" always; # Uncomment this only after you get HTTPS working. # add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; diff --git a/scripts/install b/scripts/install index c02af93..c238615 100755 --- a/scripts/install +++ b/scripts/install @@ -26,7 +26,7 @@ path_url="/" admin=$YNH_APP_ARG_ADMIN admin_email=$(ynh_user_get_info $admin 'mail') is_public=$YNH_APP_ARG_IS_PUBLIC -random_key=$(ynh_string_random 64) +random_key=$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 64 | head -n 1) name=$YNH_APP_ARG_NAME