import org.cacert.gigi.pages.LoginPage;
import org.cacert.gigi.pages.MainPage;
import org.cacert.gigi.pages.Page;
-import org.cacert.gigi.pages.PolicyRedir;
import org.cacert.gigi.pages.TestSecure;
import org.cacert.gigi.pages.Verify;
import org.cacert.gigi.pages.account.MailAdd;
import org.cacert.gigi.pages.account.MyDetails;
import org.cacert.gigi.pages.main.RegisterPage;
import org.cacert.gigi.pages.wot.AssurePage;
+import org.cacert.gigi.util.ServerConstants;
import org.eclipse.jetty.util.log.Log;
public class Gigi extends HttpServlet {
pages.put(MailCertificates.PATH, new MailCertificates());
pages.put(MyDetails.PATH, new MyDetails());
pages.put(RegisterPage.PATH, new RegisterPage());
- pages.put(PolicyRedir.PATH, new PolicyRedir());
pages.put(MailOverview.DEFAULT_PATH, new MailOverview(
"My email addresses"));
pages.put(MailAdd.DEFAULT_PATH, new MailAdd("Add new email"));
hsr.addHeader("Access-Control-Allow-Origin",
"http://cacert.org https://localhost");
hsr.addHeader("Access-Control-Max-Age", "60");
- // hsr.addHeader("Content-Security-Policy",
- // "default-src 'self'; report-uri https://felix.dogcraft.de/report.php");
+ hsr.addHeader("Content-Security-Policy", "default-src 'self' https://"
+ + ServerConstants.getStaticHostNamePort()
+ + " https://www.cacert.org/*;frame-ancestors 'none'");
+ // ;report-uri https://felix.dogcraft.de/report.php
}
}