|  | // Copyright (c) 2018, Rubén Rincón | 
|  | // All rights reserved. | 
|  | // | 
|  | // Redistribution and use in source and binary forms, with or without | 
|  | // modification, are permitted provided that the following conditions are met: | 
|  | // | 
|  | //     * Redistributions of source code must retain the above copyright notice, | 
|  | //       this list of conditions and the following disclaimer. | 
|  | //     * Redistributions in binary form must reproduce the above copyright | 
|  | //       notice, this list of conditions and the following disclaimer in the | 
|  | //       documentation and/or other materials provided with the distribution. | 
|  | // | 
|  | // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" | 
|  | // AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | 
|  | // IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | 
|  | // ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE | 
|  | // LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR | 
|  | // CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF | 
|  | // SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS | 
|  | // INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN | 
|  | // CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) | 
|  | // ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE | 
|  | // POSSIBILITY OF SUCH DAMAGE. | 
|  |  | 
|  | const _ = require('underscore'); | 
|  |  | 
|  | const data = { | 
|  | 'default-src': ["'self'", 'https://*.godbolt.org', 'localhost:*', 'https://*.compiler-explorer.com'], | 
|  | 'style-src': ["'self'", "'unsafe-inline'", 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com'], | 
|  | 'script-src': ["'self'", "'unsafe-inline'", 'data:', 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com', | 
|  | 'https://*.twitter.com', 'https://www.google-analytics.com', | 
|  | 'https://apis.google.com', 'https://ssl.google-analytics.com', 'https://sentry.io/'], | 
|  | 'img-src': ["'self'", 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com', 'data:', 'https://www.google-analytics.com/', | 
|  | 'https://syndication.twitter.com', 'https://ssl.google-analytics.com', 'https://csi.gstatic.com'], | 
|  | 'font-src': ["'self'", 'data:', 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com', 'https://fonts.gstatic.com', | 
|  | 'https://themes.googleusercontent.com'], | 
|  | 'frame-src': ["'self'", 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com', 'https://www.google-analytics.com', | 
|  | 'https://accounts.google.com/', 'https://content.googleapis.com/', | 
|  | 'https://sentry.io', 'https://platform.twitter.com/', 'https://syndication.twitter.com/'], | 
|  | 'connect-src': ["'self'", '*', 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com', 'https://api.github.com'], | 
|  | 'media-src': ["'self'", 'https://ssl.gstatic.com', 'https://*.godbolt.org', 'localhost:*', | 
|  | 'https://*.compiler-explorer.com'] | 
|  | }; | 
|  |  | 
|  | module.exports = { | 
|  | data: data, | 
|  | policy: _.map(data, (value, policyKey) => `${policyKey} ${value.join(' ')}`).join(';') | 
|  | }; |